CVE-2015-7540: High severity samba vulnerability
A denial-of-service vulnerability for the AD-DC due to insuffiecient checking on asn1 memory allocation was reported.
Upstream bug:
https://bugzilla.samba.org/showbug.cgi?id=9187
Other sources
The LDAP server in the AD domain controller in Samba 4.x before 4.1.22 does not check return values to ensure successful ASN.1 memory allocation, which allows remote attackers to cause a denial of service (memory consumption and daemon crash) via crafted packets.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7540?
CVE-2015-7540 has a severity rating of medium due to its potential for denial-of-service attacks.
How do I fix CVE-2015-7540?
To fix CVE-2015-7540, upgrade Samba to version 4.1.22 or 4.2.0 or later.
What systems are affected by CVE-2015-7540?
CVE-2015-7540 affects Samba versions prior to 4.1.22 and 4.2.0, and specific Ubuntu and Debian versions.
What kind of vulnerability is CVE-2015-7540?
CVE-2015-7540 is classified as a denial-of-service vulnerability related to insufficient ASN.1 memory allocation checks.
Is there a workaround for CVE-2015-7540?
There are no published workarounds for CVE-2015-7540; the recommended action is to apply the patch or upgrade.