ISOMAN

CVE

CVE-2015-0240

The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc5 performs a free operation on an uninitialized stack pointer, which allows remote attackers to execute arbitrary code via crafted Netlogon packets that use the ServerPasswordSet RPC API, as demonstrated by packets reaching the _netr_ServerPasswordSet function in rpc_server/netlogon/srv_netlog_nt.c.

Severity
HIGH
CVSS
10
Published
Modified

Linked Releases

References

  1. http://advisories.mageia.org/MGASA-2015-0084.html
  2. http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00028.html
  3. http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00030.html
  4. http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00031.html
  5. http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00035.html
  6. http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00042.html
  7. http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00047.html
  8. http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00048.html
  9. http://marc.info/?l=bugtraq&m=142722696102151&w=2
  10. http://marc.info/?l=bugtraq&m=143039217203031&w=2
  11. http://rhn.redhat.com/errata/RHSA-2015-0249.html
  12. http://rhn.redhat.com/errata/RHSA-2015-0250.html
  13. http://rhn.redhat.com/errata/RHSA-2015-0251.html
  14. http://rhn.redhat.com/errata/RHSA-2015-0252.html
  15. http://rhn.redhat.com/errata/RHSA-2015-0253.html
  16. http://rhn.redhat.com/errata/RHSA-2015-0254.html
  17. http://rhn.redhat.com/errata/RHSA-2015-0255.html
  18. http://rhn.redhat.com/errata/RHSA-2015-0256.html
  19. http://rhn.redhat.com/errata/RHSA-2015-0257.html
  20. http://security.gentoo.org/glsa/glsa-201502-15.xml