ldb before 1.1.24, as used in the AD LDAP server...
Vulnerability Description
ldb before 1.1.24, as used in the AD LDAP server in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, mishandles string lengths, which allows remote attackers to obtain sensitive information from daemon heap memory by sending crafted packets and then reading (1) an error message or (2) a database value.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2015-5330
Credits & Attribution
No credits recorded in the NVD database.
References
- https://git.samba.org/?p=samba.git%3Ba=commit%3Bh=f36cb71c330a52106e36028b3029d952257baf15
- https://git.samba.org/?p=samba.git%3Ba=commit%3Bh=ba5dbda6d0174a59d221c45cca52ecd232820d48
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00042.html
- http://www.ubuntu.com/usn/USN-2855-2
- https://git.samba.org/?p=samba.git%3Ba=commit%3Bh=a118d4220ed85749c07fb43c1229d9e2fecbea6b
- http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00002.html
- http://www.ubuntu.com/usn/USN-2856-1
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00019.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00020.html
- https://bugzilla.redhat.com/show_bug.cgi?id=1281326
- https://git.samba.org/?p=samba.git%3Ba=commit%3Bh=0454b95657846fcecf0f51b6f1194faac02518bd
- https://www.samba.org/samba/security/CVE-2015-5330.html
- http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00017.html
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00032.html
- https://git.samba.org/?p=samba.git%3Ba=commit%3Bh=538d305de91e34a2938f5f219f18bf0e1918763f
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00047.html
- http://www.securitytracker.com/id/1034493
- http://www.debian.org/security/2016/dsa-3433
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00048.html
- https://security.gentoo.org/glsa/201612-47
- http://www.securityfocus.com/bid/79734
- http://www.ubuntu.com/usn/USN-2855-1
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00033.html
- https://git.samba.org/?p=samba.git%3Ba=commit%3Bh=7f51ec8c4ed9ba1f53d722e44fb6fb3cde933b72
More from samba
View All →Affected Vendor
samba
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.