1
PublicDateAtUSN: 2015-12-16
2
Candidate: CVE-2015-7540
6
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7540
7
https://www.samba.org/samba/security/CVE-2015-7540.html
8
https://usn.ubuntu.com/usn/usn-2855-1
10
The LDAP server in the AD domain controller in Samba 4.x before 4.1.22 does
11
not check return values to ensure successful ASN.1 memory allocation, which
12
allows remote attackers to cause a denial of service (memory consumption
13
and daemon crash) via crafted packets.
16
mdeslaur> says 4.0.0 to 4.1.21
18
https://bugzilla.samba.org/show_bug.cgi?id=9187
24
upstream: https://git.samba.org/?p=samba.git;a=commit;h=530d50a1abdcdf4d1775652d4c456c1274d83d8d (4.1)
25
upstream: https://git.samba.org/?p=samba.git;a=commit;h=9d989c9dd7a5b92d0c5d65287935471b83b6e884 (4.1)
26
upstream_samba: released (4.1.22)
27
precise_samba: not-affected (2:3.6.3-2ubuntu2.12)
28
precise/esm_samba: not-affected (2:3.6.3-2ubuntu2.12)
29
trusty_samba: released (2:4.1.6+dfsg-1ubuntu2.14.04.11)
30
vivid_samba: released (2:4.1.13+dfsg-4ubuntu3.1)
31
vivid/stable-phone-overlay_samba: DNE
32
vivid/ubuntu-core_samba: DNE
33
wily_samba: released (2:4.1.17+dfsg-4ubuntu3.1)
34
xenial_samba: released (2:4.3.3+dfsg-1ubuntu1)
35
yakkety_samba: released (2:4.3.3+dfsg-1ubuntu1)
36
zesty_samba: released (2:4.3.3+dfsg-1ubuntu1)
37
devel_samba: released (2:4.3.3+dfsg-1ubuntu1)
40
upstream_samba4: released (4.1.22)
41
precise_samba4: ignored (reached end-of-life)
42
precise/esm_samba4: DNE (precise was needed)
45
vivid/stable-phone-overlay_samba4: DNE
46
vivid/ubuntu-core_samba4: DNE