icon

We found results for “

CVE-2015-3223

Good to know:

icon

Date: December 29, 2015

The ldb_wildcard_compare function in ldb_match.c in ldb before 1.1.24, as used in the AD LDAP server in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, mishandles certain zero values, which allows remote attackers to cause a denial of service (infinite loop) via crafted packets.

Language: C

Severity Score

Related Resources (24)

Severity Score

Weakness Type (CWE)

Numeric Errors

CWE-189

Resource Management Errors

CWE-399

Top Fix

icon

Upgrade Version

Upgrade to version Samba:4.3.3,4.2.7,4.1.22;ldb:1.1.24

Learn More

CVSS v3

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): NONE
Integrity (I): NONE
Availability (A): LOW

CVSS v2

Base Score:
Access Vector (AV): NETWORK
Access Complexity (AC): LOW
Authentication (AU): NONE
Confidentiality (C): NONE
Integrity (I): NONE
Availability (A): PARTIAL
Additional information:

Do you need more information?

Contact Us