PT-2015-3398 · Samba+5 · Samba+6

Thilo Uttendorfer

·

Published

2015-12-16

·

Updated

2024-06-15

·

CVE-2015-3223

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions ldb versions prior to 1.1.24 Samba 4.1.x versions prior to 4.1.22 Samba 4.2.x versions prior to 4.2.7 Samba 4.3.x versions prior to 4.3.3
Description The issue is related to the ldb wildcard compare function, which mishandles certain zero values. This allows remote attackers to cause a denial of service, specifically an infinite loop, by sending crafted packets. The problem is associated with an error in handling numbers.
Recommendations For ldb versions prior to 1.1.24, update to version 1.1.24 or later. For Samba 4.1.x versions prior to 4.1.22, update to version 4.1.22 or later. For Samba 4.2.x versions prior to 4.2.7, update to version 4.2.7 or later. For Samba 4.3.x versions prior to 4.3.3, update to version 4.3.3 or later.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-2137
ALT-PU-2015-2138
ALT-PU-2015-2139
BDU:2021-01299
CESA-2016_0009
CVE-2015-3223
DSA-3433-1
ECHO-DFE2-71FB-0288
MGASA-2016-0094
OPENSUSE-SU-2015_2354-1
OPENSUSE-SU-2015_2356-1
OPENSUSE-SU-2016_1064-1
OPENSUSE-SU-2024:10069-1
OPENSUSE-SU-2024:10074-1
RHSA-2016:0009
RHSA-2016:0014
RHSA-2016_0009
SUSE-SU-2015:2304-1
SUSE-SU-2015:2305-1
USN-2855-1
USN-2855-2
USN-2856-1

Affected Products

Alt Linux
Centos
Red Hat
Samba
Suse
Ubuntu
Ldb