7.5
CVSSv3

CVE-2015-7540

Published: 29/12/2015 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The LDAP server in the AD domain controller in Samba 4.x prior to 4.1.22 does not check return values to ensure successful ASN.1 memory allocation, which allows remote malicious users to cause a denial of service (memory consumption and daemon crash) via crafted packets.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

samba samba

canonical ubuntu linux 15.10

canonical ubuntu linux 15.04

canonical ubuntu linux 14.04

canonical ubuntu linux 12.04

debian debian linux 8.0

debian debian linux 7.0

Vendor Advisories

Synopsis Moderate: samba security update Type/Severity Security Advisory: Moderate Topic Updated samba packages that fix multiple security issues are now availablefor Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having Moderate securityimpact Common Vulnerability Scoring Sys ...
Synopsis Moderate: samba4 security update Type/Severity Security Advisory: Moderate Topic Updated samba4 packages that fix multiple security issues are now availablefor Red Hat Enterprise Linux 6Red Hat Product Security has rated this update as having Moderate securityimpact Common Vulnerability Scoring S ...
Several security issues were fixed in Samba ...
USN-2855-1 introduced a regression in Samba ...
Several vulnerabilities have been discovered in Samba, a SMB/CIFS file, print, and login server for Unix The Common Vulnerabilities and Exposures project identifies the following issues: CVE-2015-3223 Thilo Uttendorfer of Linux Information Systems AG discovered that a malicious request can cause the Samba LDAP server to hang, spinning ...
A denial of service flaw was found in the LDAP server provided by the AD DC in the Samba process daemon A remote attacker could exploit this flaw by sending a specially crafted packet, which could cause the server to consume an excessive amount of memory and crash ...