CVE-2015-0240
published 2015-02-24CVE-2015-0240: The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc5 performs…
PriorityP279critical10CVSS 2.0
AVNACLAuNCCICAC
EXPLOIT
EPSS
87.64%
99.7th percentile
The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc5 performs a free operation on an uninitialized stack pointer, which allows remote attackers to execute arbitrary code via crafted Netlogon packets that use the ServerPasswordSet RPC API, as demonstrated by packets reaching the _netr_ServerPasswordSet function in rpc_server/netlogon/srv_netlog_nt.c.
Affected
98 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | samba | < samba 2:4.1.17+dfsg-1 (bookworm) | samba 2:4.1.17+dfsg-1 (bookworm) |
| novell | suse_linux_enterprise_desktop | — | — |
| novell | suse_linux_enterprise_server | — | — |
| novell | suse_linux_enterprise_software_development_kit | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Alert on SMB connections negotiating only 'NT LM 0.12' dialect followed by a netlogon pipe open — the exploit forces this dialect exclusively. ↗
- →A Metasploit auxiliary scanner module exists for detecting vulnerable Samba targets: smb_uninit_cred. ↗
- →The exploit sends crafted Netlogon packets with a PrimaryName ReferentID of 0 to trigger the uninitialized stack pointer free; monitor for NetrServerPasswordSet (Opnum 6) calls with a null PrimaryName pointer from unexpected sources. ↗
- →The vulnerability is in smbd's Netlogon server (_netr_ServerPasswordSet); monitor smbd process for unexpected crashes or privilege escalation events originating from port 445. ↗
- ·On Samba 4.0.0 and above, the netlogon RPC server can be disabled as a workaround by adding 'rpc_server:netlogon=disabled' to the [global] section of smb.conf. This workaround is NOT available for Samba 3.6.x and earlier. ↗
- ·On Red Hat Enterprise Linux 7, the vulnerable code path is only reached after a memory allocation failure, making exploitation more difficult — but the system is still considered affected with Important impact. ↗
- ·The exploit heap-spray uses fragmented RPC requests with a fixed Samba RPC fragment size of 4280 bytes; detection rules should account for abnormally large or fragmented netlogon RPC PDUs over SMB. ↗
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0CRITICAL
vendor_redhat10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
samba: talloc free on uninitialized stack pointer in netlogon server could lead to remote-code execution
vendor_redhat·2015-02-23·CVSS 10.0
CVE-2015-0240 [CRITICAL] CWE-119 samba: talloc free on uninitialized stack pointer in netlogon server could lead to remote-code execution
samba: talloc free on uninitialized stack pointer in netlogon server could lead to remote-code execution
The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc5 performs a free operation on an uninitialized stack pointer, which allows remote attackers to execute arbitrary code via crafted Netlogon packets that use the ServerPasswordSet RPC API, as demonstrated by packets reaching the _netr_ServerPasswordSet function in rpc_server/netlogon/srv_netlog_nt.c.
An uninitialized pointer use flaw was found in the Samba daemon (smbd). A malicious Samba client could send specially crafted netlogon packets that, when processed by smbd, could potentially lead to arbitrary code execution with the privileges
Ubuntu
Samba vulnerability
vendor_ubuntu·2015-02-23
CVE-2015-0240 Samba vulnerability
Title: Samba vulnerability
Summary: Samba could be made to run programs as an administrator if it received
specially crafted network traffic.
Richard van Eeden discovered that the Samba smbd file services incorrectly
handled memory. A remote attacker could use this issue to possibly execute
arbitrary code with root privileges.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2015-0240: samba - The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.2...
vendor_debian·2015·CVSS 10.0
CVE-2015-0240 [CRITICAL] CVE-2015-0240: samba - The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.2...
The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc5 performs a free operation on an uninitialized stack pointer, which allows remote attackers to execute arbitrary code via crafted Netlogon packets that use the ServerPasswordSet RPC API, as demonstrated by packets reaching the _netr_ServerPasswordSet function in rpc_server/netlogon/srv_netlog_nt.c.
Scope: local
bookworm: resolved (fixed in 2:4.1.17+dfsg-1)
bullseye: resolved (fixed in 2:4.1.17+dfsg-1)
forky: resolved (fixed in 2:4.1.17+dfsg-1)
sid: resolved (fixed in 2:4.1.17+dfsg-1)
trixie: resolved (fixed in 2:4.1.17+dfsg-1)
GHSA
GHSA-wjcr-wjqx-g6rq: The Netlogon server implementation in smbd in Samba 3
ghsa_unreviewed·2022-05-14
CVE-2015-0240 [HIGH] GHSA-wjcr-wjqx-g6rq: The Netlogon server implementation in smbd in Samba 3
The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc5 performs a free operation on an uninitialized stack pointer, which allows remote attackers to execute arbitrary code via crafted Netlogon packets that use the ServerPasswordSet RPC API, as demonstrated by packets reaching the _netr_ServerPasswordSet function in rpc_server/netlogon/srv_netlog_nt.c.
OSV
CVE-2015-0240: The Netlogon server implementation in smbd in Samba 3
osv·2015-02-24·CVSS 10.0
CVE-2015-0240 [CRITICAL] CVE-2015-0240: The Netlogon server implementation in smbd in Samba 3
The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc5 performs a free operation on an uninitialized stack pointer, which allows remote attackers to execute arbitrary code via crafted Netlogon packets that use the ServerPasswordSet RPC API, as demonstrated by packets reaching the _netr_ServerPasswordSet function in rpc_server/netlogon/srv_netlog_nt.c.
No detection rules found.
Exploit-DB
Samba < 3.6.2 (x86) - Denial of Service (PoC)
exploitdb·2015-04-13·CVSS 10.0
CVE-2015-0240 [CRITICAL] Samba < 3.6.2 (x86) - Denial of Service (PoC)
Samba in_data.pdu.data. the size is 0x10e8 (included glibc heap header 4 bytes)
- this might not be allocated here because its size might fit in freed hole
- all fragment should be same size to prevent talloc_realloc() changed pdu.data size
- so last fragment should be padded
- ndr DATA_BLOB. the size is 0x10d0 (included glibc heap header 4 bytes)
- this might not be allocated here because its size might fit in freed hole
- p->in_data.data.data. the size is our netlogon data
- for 8K payload, the size is 0x2168 (included glibc heap header 4 bytes)
- this data is allocated by realloc(), grew by each fragment. so this memory
block is not allocated by mmapped even the size is very big.
- pool layout for interested data
- r->out offset from pool (talloc header) is 0x13c0
- r->out.return_authen
Metasploit
Samba _netr_ServerPasswordSet Uninitialized Credential State
metasploit
Samba _netr_ServerPasswordSet Uninitialized Credential State
Samba _netr_ServerPasswordSet Uninitialized Credential State
This module checks if a Samba target is vulnerable to an uninitialized variable creds vulnerability.
Bugzilla
CVE-2015-0240 samba: talloc free on uninitialized stack pointer in netlogon server could lead to remote-code execution
bugzilla·2015-02-11·CVSS 10.0
CVE-2015-0240 [CRITICAL] CVE-2015-0240 samba: talloc free on uninitialized stack pointer in netlogon server could lead to remote-code execution
CVE-2015-0240 samba: talloc free on uninitialized stack pointer in netlogon server could lead to remote-code execution
As per upstream samba advisory:
All versions of Samba from 3.5.0 to 4.2.0rc4 are vulnerable to an unexpected code execution vulnerability in the smbd file server daemon.
A malicious client could send packets that may set up the stack in such a way that the freeing of memory in a subsequent anonymous netlogon packet could allow execution of arbitrary code. This code would execute with root privileges.
Discussion:
Created attachment 990468
Upstream patch against git-master
---
Acknowledgements:
Red Hat would like to thank the Samba project for reporting this issue. Upstream acknowledges Richard van Eeden of Microsoft Vulnerability Research as the original reporter of
arXiv
Static Detection of Uninitialized Stack Variables in Binary Code
arxiv_fulltext·2020-07-05
Static Detection of Uninitialized Stack Variables in Binary Code
Static Detection of Uninitialized Stack Variables in Binary Code
Static Detection of Uninitialized Stack Variables in Binary Code
Behrad Garmany
Martin Stoffel
Robert Gawlik
Thorsten Holz
Garmany et al.
Horst Görtz Institute for IT-Security (HGI)
Ruhr-Universität Bochum, Germany
\firstname.lastname\@rub.de
## Abstract
More than two decades after the first stack smashing attacks, memory
corruption vulnerabilities utilizing stack anomalies are still prevalent and
play an important role in practice. Among such vulnerabilities, uninitialized
variables play an exceptional role due to their unpleasant property of
unpredictability: as compilers are tailored to operate fast, costly
interprocedural analysis procedures are not used in practice to detect such
vulnerabilities. As a result, comple
http://advisories.mageia.org/MGASA-2015-0084.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-02/msg00028.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-02/msg00030.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-02/msg00031.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-02/msg00035.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00042.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00047.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00048.htmlhttp://marc.info/?l=bugtraq&m=142722696102151&w=2http://marc.info/?l=bugtraq&m=143039217203031&w=2http://rhn.redhat.com/errata/RHSA-2015-0249.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0250.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0251.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0252.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0253.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0254.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0255.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0256.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0257.htmlhttp://security.gentoo.org/glsa/glsa-201502-15.xmlhttp://www.debian.org/security/2015/dsa-3171http://www.mandriva.com/security/advisories?name=MDVSA-2015:081http://www.mandriva.com/security/advisories?name=MDVSA-2015:082http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.htmlhttp://www.securityfocus.com/bid/72711http://www.securitytracker.com/id/1031783http://www.slackware.com/security/viewer.php?l=slackware-security&y=2015&m=slackware-security.360345http://www.ubuntu.com/usn/USN-2508-1https://access.redhat.com/articles/1346913https://bugzilla.redhat.com/show_bug.cgi?id=1191325https://securityblog.redhat.com/2015/02/23/samba-vulnerability-cve-2015-0240/https://support.lenovo.com/product_security/samba_remote_vulnhttps://support.lenovo.com/us/en/product_security/samba_remote_vulnhttps://www.exploit-db.com/exploits/36741/https://www.samba.org/samba/security/CVE-2015-0240http://advisories.mageia.org/MGASA-2015-0084.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-02/msg00028.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-02/msg00030.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-02/msg00031.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-02/msg00035.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00042.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00047.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00048.htmlhttp://marc.info/?l=bugtraq&m=142722696102151&w=2http://marc.info/?l=bugtraq&m=143039217203031&w=2http://rhn.redhat.com/errata/RHSA-2015-0249.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0250.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0251.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0252.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0253.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0254.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0255.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0256.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0257.htmlhttp://security.gentoo.org/glsa/glsa-201502-15.xmlhttp://www.debian.org/security/2015/dsa-3171http://www.mandriva.com/security/advisories?name=MDVSA-2015:081http://www.mandriva.com/security/advisories?name=MDVSA-2015:082http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.htmlhttp://www.securityfocus.com/bid/72711http://www.securitytracker.com/id/1031783http://www.slackware.com/security/viewer.php?l=slackware-security&y=2015&m=slackware-security.360345http://www.ubuntu.com/usn/USN-2508-1https://access.redhat.com/articles/1346913https://bugzilla.redhat.com/show_bug.cgi?id=1191325https://security.netapp.com/advisory/ntap-20250509-0001/https://securityblog.redhat.com/2015/02/23/samba-vulnerability-cve-2015-0240/https://support.lenovo.com/product_security/samba_remote_vulnhttps://support.lenovo.com/us/en/product_security/samba_remote_vulnhttps://www.exploit-db.com/exploits/36741/https://www.samba.org/samba/security/CVE-2015-0240
2015-02-24
Published