PT-2015-1312 · Samba Team+7 · Samba+6

Richard Van Eeden

·

Published

2015-02-18

·

Updated

2024-06-15

·

CVE-2015-0240

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Samba versions 3.5.x through 3.6.24 Samba versions 4.0.x through 4.0.24 Samba versions 4.1.x through 4.1.16 Samba versions 4.2.x through 4.2.0rc4
Description The issue is related to errors in the code of the Samba network interaction package, specifically in the netr ServerPasswordSet function. Exploitation of this issue may allow a remote attacker to execute arbitrary code with administrator privileges using a specially crafted remote procedure call to the ServerPasswordSet RPC API. The vulnerability exists due to the free operation on an uninitialized stack pointer in the Netlogon server implementation in smbd. This allows remote attackers to execute arbitrary code via crafted Netlogon packets that use the ServerPasswordSet RPC API.
Recommendations For Samba versions 3.5.x through 3.6.24, update to version 3.6.25 or later. For Samba versions 4.0.x through 4.0.24, update to version 4.0.25 or later. For Samba versions 4.1.x through 4.1.16, update to version 4.1.17 or later. For Samba versions 4.2.x through 4.2.0rc4, update to version 4.2.0rc5 or later.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-1196
BDU:2015-10377
CESA-2015_0250
CESA-2015_0251
CESA-2015_0252
CVE-2015-0240
DLA-156-1
DSA-3171-1
ECHO-2110-1C89-9BEF
ELSA-2015-0250
ELSA-2015-0251
ELSA-2015-0252
HPSBUX03320
MGASA-2015-0084
OPENSUSE-SU-2015_0375-1
OPENSUSE-SU-2016_1064-1
OPENSUSE-SU-2016_1106-1
OPENSUSE-SU-2024:10069-1
RHSA-2015:0249
RHSA-2015:0250
RHSA-2015:0251
RHSA-2015:0252
RHSA-2015:0253
RHSA-2015:0254
RHSA-2015:0255
RHSA-2015:0256
RHSA-2015:0257
RHSA-2015_0249
RHSA-2015_0250
RHSA-2015_0251
RHSA-2015_0252
SUSE-SU-2015:0353-1
SUSE-SU-2015:0371-1
SUSE-SU-2015:0386-1
SUSE-SU-2015_0353-1
SUSE-SU-2015_0371-1
SUSE-SU-2015_0386-1
USN-2508-1

Affected Products

Alt Linux
Centos
Hp-Ux
Red Hat
Samba
Suse
Ubuntu