CVE-2015-5330
published 2015-12-29CVE-2015-5330: ldb before 1.1.24, as used in the AD LDAP server in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, mishandles string lengths, which…
PriorityP343high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
6.11%
92.7th percentile
ldb before 1.1.24, as used in the AD LDAP server in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, mishandles string lengths, which allows remote attackers to obtain sensitive information from daemon heap memory by sending crafted packets and then reading (1) an error message or (2) a database value.
Affected
65 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ldb | < ldb 2:1.1.24-1 (bullseye) | ldb 2:1.1.24-1 (bullseye) |
| debian | samba | < ldb 2:1.1.24-1 (bullseye) | ldb 2:1.1.24-1 (bullseye) |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r5pq-r3w3-76q7: ldb before 1
ghsa_unreviewed·2022-05-17
CVE-2015-5330 [HIGH] CWE-200 GHSA-r5pq-r3w3-76q7: ldb before 1
ldb before 1.1.24, as used in the AD LDAP server in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, mishandles string lengths, which allows remote attackers to obtain sensitive information from daemon heap memory by sending crafted packets and then reading (1) an error message or (2) a database value.
OSV
samba regression
osv·2016-02-16·CVSS 5.3
CVE-2015-5252 [MEDIUM] samba regression
samba regression
USN-2855-1 fixed vulnerabilities in Samba. The upstream fix for
CVE-2015-5252 introduced a regression in certain specific environments.
This update fixes the problem.
Original advisory details:
Thilo Uttendorfer discovered that the Samba LDAP server incorrectly handled
certain packets. A remote attacker could use this issue to cause the LDAP
server to stop responding, resulting in a denial of service. This issue
only affected Ubuntu 14.04 LTS, Ubuntu 15.04 and Ubuntu 15.10.
(CVE-2015-3223)
Jan Kasprzak discovered that Samba incorrectly handled certain symlinks. A
remote attacker could use this issue to access files outside the exported
share path. (CVE-2015-5252)
Stefan Metzmacher discovered that Samba did not enforce signing when
creating encrypted connections. If a
OSV
samba vulnerabilities
osv·2016-01-05·CVSS 5.3
CVE-2015-3223 [MEDIUM] samba vulnerabilities
samba vulnerabilities
Thilo Uttendorfer discovered that the Samba LDAP server incorrectly handled
certain packets. A remote attacker could use this issue to cause the LDAP
server to stop responding, resulting in a denial of service. This issue
only affected Ubuntu 14.04 LTS, Ubuntu 15.04 and Ubuntu 15.10.
(CVE-2015-3223)
Jan Kasprzak discovered that Samba incorrectly handled certain symlinks. A
remote attacker could use this issue to access files outside the exported
share path. (CVE-2015-5252)
Stefan Metzmacher discovered that Samba did not enforce signing when
creating encrypted connections. If a remote attacker were able to perform a
machine-in-the-middle attack, this flaw could be exploited to view sensitive
information. (CVE-2015-5296)
It was discovered that Samba incorrectly perf
OSV
ldb vulnerabilities
osv·2016-01-05·CVSS 5.3
CVE-2015-3223 [MEDIUM] ldb vulnerabilities
ldb vulnerabilities
Thilo Uttendorfer discovered that the ldb incorrectly handled certain zero
values. A remote attacker could use this issue to cause applications using
ldb, such as Samba, to stop responding, resulting in a denial of service.
(CVE-2015-3223)
Douglas Bagnall discovered that ldb incorrectly handled certain string
lengths. A remote attacker could use this issue to possibly access
sensitive information from memory of applications using ldb, such as Samba.
(CVE-2015-5330)
OSV
CVE-2015-5330: ldb before 1
osv·2015-12-29·CVSS 7.5
CVE-2015-5330 [HIGH] CVE-2015-5330: ldb before 1
ldb before 1.1.24, as used in the AD LDAP server in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, mishandles string lengths, which allows remote attackers to obtain sensitive information from daemon heap memory by sending crafted packets and then reading (1) an error message or (2) a database value.
Ubuntu
Samba regression
vendor_ubuntu·2016-02-16·CVSS 5.3
CVE-2015-5252 [MEDIUM] Samba regression
Title: Samba regression
Summary: USN-2855-1 introduced a regression in Samba.
USN-2855-1 fixed vulnerabilities in Samba. The upstream fix for
CVE-2015-5252 introduced a regression in certain specific environments.
This update fixes the problem.
Original advisory details:
Thilo Uttendorfer discovered that the Samba LDAP server incorrectly handled
certain packets. A remote attacker could use this issue to cause the LDAP
server to stop responding, resulting in a denial of service. This issue
only affected Ubuntu 14.04 LTS, Ubuntu 15.04 and Ubuntu 15.10.
(CVE-2015-3223)
Jan Kasprzak discovered that Samba incorrectly handled certain symlinks. A
remote attacker could use this issue to access files outside the exported
share path. (CVE-2015-5252)
Stefan Metzmacher discovered that Samba did
Ubuntu
ldb vulnerabilities
vendor_ubuntu·2016-01-05·CVSS 5.3
CVE-2015-3223 [MEDIUM] ldb vulnerabilities
Title: ldb vulnerabilities
Summary: Several security issues were fixed in ldb.
Thilo Uttendorfer discovered that the ldb incorrectly handled certain zero
values. A remote attacker could use this issue to cause applications using
ldb, such as Samba, to stop responding, resulting in a denial of service.
(CVE-2015-3223)
Douglas Bagnall discovered that ldb incorrectly handled certain string
lengths. A remote attacker could use this issue to possibly access
sensitive information from memory of applications using ldb, such as Samba.
(CVE-2015-5330)
Instructions: After a standard system update you need to restart applications using ldb,
such as Samba, to make all the necessary changes.
Ubuntu
Samba vulnerabilities
vendor_ubuntu·2016-01-05·CVSS 5.3
CVE-2015-3223 [MEDIUM] Samba vulnerabilities
Title: Samba vulnerabilities
Summary: Several security issues were fixed in Samba.
Thilo Uttendorfer discovered that the Samba LDAP server incorrectly handled
certain packets. A remote attacker could use this issue to cause the LDAP
server to stop responding, resulting in a denial of service. This issue
only affected Ubuntu 14.04 LTS, Ubuntu 15.04 and Ubuntu 15.10.
(CVE-2015-3223)
Jan Kasprzak discovered that Samba incorrectly handled certain symlinks. A
remote attacker could use this issue to access files outside the exported
share path. (CVE-2015-5252)
Stefan Metzmacher discovered that Samba did not enforce signing when
creating encrypted connections. If a remote attacker were able to perform a
machine-in-the-middle attack, this flaw could be exploited to view sensitive
information.
Red Hat
libldb: remote memory read in the Samba LDAP server
vendor_redhat·2015-12-16·CVSS 7.5
CVE-2015-5330 [HIGH] CWE-135 libldb: remote memory read in the Samba LDAP server
libldb: remote memory read in the Samba LDAP server
ldb before 1.1.24, as used in the AD LDAP server in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, mishandles string lengths, which allows remote attackers to obtain sensitive information from daemon heap memory by sending crafted packets and then reading (1) an error message or (2) a database value.
A memory-read flaw was found in the way the libldb library processed LDB DN records with a null byte. An authenticated, remote attacker could use this flaw to read heap-memory pages from the server.
Package: libldb (Red Hat Enterprise Linux 5) - Will not fix
Package: samba (Red Hat Enterprise Linux 5) - Not affected
Package: samba3x (Red Hat Enterprise Linux 5) - Not affected
Package: samba (Red Hat Enterprise Linu
Debian
CVE-2015-5330: ldb - ldb before 1.1.24, as used in the AD LDAP server in Samba 4.x before 4.1.22, 4.2...
vendor_debian·2015·CVSS 7.5
CVE-2015-5330 [HIGH] CVE-2015-5330: ldb - ldb before 1.1.24, as used in the AD LDAP server in Samba 4.x before 4.1.22, 4.2...
ldb before 1.1.24, as used in the AD LDAP server in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, mishandles string lengths, which allows remote attackers to obtain sensitive information from daemon heap memory by sending crafted packets and then reading (1) an error message or (2) a database value.
Scope: local
bullseye: resolved (fixed in 2:1.1.24-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-5330 libldb: samba: Remote memory read in Samba LDAP server [fedora-all]
bugzilla·2015-12-16·CVSS 7.5
CVE-2015-5330 [HIGH] CVE-2015-5330 libldb: samba: Remote memory read in Samba LDAP server [fedora-all]
CVE-2015-5330 libldb: samba: Remote memory read in Samba LDAP server [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions
Bugzilla
CVE-2015-5330 samba, libldb: remote memory read in the Samba LDAP server
bugzilla·2015-11-12·CVSS 7.5
CVE-2015-5330 [HIGH] CVE-2015-5330 samba, libldb: remote memory read in the Samba LDAP server
CVE-2015-5330 samba, libldb: remote memory read in the Samba LDAP server
It was reported that when adding an LDB DN to the database, that if a \00 (null byte) is used, remote memory can be read due to a combination of talloc_strdup() and a length assignment.
Upstream bug:
https://bugzilla.samba.org/show_bug.cgi?id=11599
Discussion:
Acknowledgements:
Red Hat would like to thank the Samba project for reporting this issue. Upstream acknowledges Douglas Bagnall as the original reporter.
---
Created libldb tracking bugs for this issue:
Affects: fedora-all [bug 1292070]
---
External References:
https://www.samba.org/samba/security/CVE-2015-5330.html
---
Upstream commits tagged with CVE-2015-5330.
There are multiple commits for libldb using this CVE id:
https://git.samba.org/?p=sa
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00019.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00032.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00033.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00042.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00047.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00048.htmlhttp://www.debian.org/security/2016/dsa-3433http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.securityfocus.com/bid/79734http://www.securitytracker.com/id/1034493http://www.ubuntu.com/usn/USN-2855-1http://www.ubuntu.com/usn/USN-2855-2http://www.ubuntu.com/usn/USN-2856-1https://bugzilla.redhat.com/show_bug.cgi?id=1281326https://git.samba.org/?p=samba.git%3Ba=commit%3Bh=0454b95657846fcecf0f51b6f1194faac02518bdhttps://git.samba.org/?p=samba.git%3Ba=commit%3Bh=538d305de91e34a2938f5f219f18bf0e1918763fhttps://git.samba.org/?p=samba.git%3Ba=commit%3Bh=7f51ec8c4ed9ba1f53d722e44fb6fb3cde933b72https://git.samba.org/?p=samba.git%3Ba=commit%3Bh=a118d4220ed85749c07fb43c1229d9e2fecbea6bhttps://git.samba.org/?p=samba.git%3Ba=commit%3Bh=ba5dbda6d0174a59d221c45cca52ecd232820d48https://git.samba.org/?p=samba.git%3Ba=commit%3Bh=f36cb71c330a52106e36028b3029d952257baf15https://security.gentoo.org/glsa/201612-47https://www.samba.org/samba/security/CVE-2015-5330.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00019.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00032.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00033.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00042.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00047.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00048.htmlhttp://www.debian.org/security/2016/dsa-3433http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.securityfocus.com/bid/79734http://www.securitytracker.com/id/1034493http://www.ubuntu.com/usn/USN-2855-1http://www.ubuntu.com/usn/USN-2855-2http://www.ubuntu.com/usn/USN-2856-1https://bugzilla.redhat.com/show_bug.cgi?id=1281326https://git.samba.org/?p=samba.git%3Ba=commit%3Bh=0454b95657846fcecf0f51b6f1194faac02518bdhttps://git.samba.org/?p=samba.git%3Ba=commit%3Bh=538d305de91e34a2938f5f219f18bf0e1918763fhttps://git.samba.org/?p=samba.git%3Ba=commit%3Bh=7f51ec8c4ed9ba1f53d722e44fb6fb3cde933b72https://git.samba.org/?p=samba.git%3Ba=commit%3Bh=a118d4220ed85749c07fb43c1229d9e2fecbea6bhttps://git.samba.org/?p=samba.git%3Ba=commit%3Bh=ba5dbda6d0174a59d221c45cca52ecd232820d48https://git.samba.org/?p=samba.git%3Ba=commit%3Bh=f36cb71c330a52106e36028b3029d952257baf15https://security.gentoo.org/glsa/201612-47https://www.samba.org/samba/security/CVE-2015-5330.html
2015-12-29
Published