PT-2015-3398 · Samba+5 · Samba+6

Thilo Uttendorfer

·

Publicado

2015-12-16

·

Atualizado

2024-06-15

·

CVE-2015-3223

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions ldb versions prior to 1.1.24 Samba 4.1.x versions prior to 4.1.22 Samba 4.2.x versions prior to 4.2.7 Samba 4.3.x versions prior to 4.3.3
Description The issue is related to the ldb wildcard compare function, which mishandles certain zero values. This allows remote attackers to cause a denial of service, specifically an infinite loop, by sending crafted packets. The problem is associated with an error in handling numbers.
Recommendations For ldb versions prior to 1.1.24, update to version 1.1.24 or later. For Samba 4.1.x versions prior to 4.1.22, update to version 4.1.22 or later. For Samba 4.2.x versions prior to 4.2.7, update to version 4.2.7 or later. For Samba 4.3.x versions prior to 4.3.3, update to version 4.3.3 or later.

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2015-2137
ALT-PU-2015-2138
ALT-PU-2015-2139
BDU:2021-01299
CESA-2016_0009
CVE-2015-3223
DSA-3433-1
ECHO-DFE2-71FB-0288
MGASA-2016-0094
OPENSUSE-SU-2015_2354-1
OPENSUSE-SU-2015_2356-1
OPENSUSE-SU-2016_1064-1
OPENSUSE-SU-2024:10069-1
OPENSUSE-SU-2024:10074-1
RHSA-2016:0009
RHSA-2016:0014
RHSA-2016_0009
SUSE-SU-2015:2304-1
SUSE-SU-2015:2305-1
USN-2855-1
USN-2855-2
USN-2856-1

Produtos afetados

Alt Linux
Centos
Red Hat
Samba
Suse
Ubuntu
Ldb