CVE-2015-7540 PUBLISHED

The LDAP server in the AD domain controller in Samba 4.x before 4.1.22 does not check return values to ensure successful ASN.1 memory allocation, which allows remote attackers to cause a denial of service (memory consumption and daemon crash) via crafted packets.

EPSS 43.30% · 97.5th percentile

Risk Scores

EPSS Score
43.30%
97.5th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSsamba0, 2:3.6.18-1ubuntu3, 2:4.0.10+dfsg-4ubuntu2
Ubuntu:16.04:LTSsamba0, 2:4.1.17+dfsg-4ubuntu2, 2:4.1.20+dfsg-1ubuntu1

Timeline

References

Open in Interactive Console →