CVE-2015-5370: Medium severity samba vulnerability
Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not properly implement the DCE-RPC layer, which allows remote attackers to perform protocol-downgrade attacks, cause a denial of service (application crash or CPU consumption), or possibly execute arbitrary code on a client system via unspecified vectors.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5370?
CVE-2015-5370 is considered to have a high severity due to its potential for denial of service and arbitrary code execution.
How do I fix CVE-2015-5370?
To fix CVE-2015-5370, upgrade Samba to version 4.2.11, 4.3.8, or 4.4.2 or later.
What types of attacks are possible with CVE-2015-5370?
CVE-2015-5370 allows for protocol-downgrade attacks, application crashes, increased CPU consumption, and possibly arbitrary code execution.
Which versions of Samba are affected by CVE-2015-5370?
CVE-2015-5370 affects Samba versions 3.x and 4.x prior to 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2.
Who is affected by CVE-2015-5370?
Organizations using vulnerable versions of Samba are at risk of exploitation from remote attackers due to CVE-2015-5370.