Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2015-0240


The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc5 performs a free operation on an uninitialized stack pointer, which allows remote attackers to execute arbitrary code via crafted Netlogon packets that use the ServerPasswordSet RPC API, as demonstrated by packets reaching the _netr_ServerPasswordSet function in rpc_server/netlogon/srv_netlog_nt.c.


Published

2015-02-24T01:59:00.050

Last Modified

2025-05-09T20:15:34.930

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 10.0 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

10.0

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-17

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System redhat enterprise_linux 5 Yes
Operating System redhat enterprise_linux 6.0 Yes
Operating System redhat enterprise_linux 7.0 Yes
Application samba samba 3.5.0 Yes
Application samba samba 3.5.1 Yes
Application samba samba 3.5.2 Yes
Application samba samba 3.5.3 Yes
Application samba samba 3.5.4 Yes
Application samba samba 3.5.5 Yes
Application samba samba 3.5.6 Yes
Application samba samba 3.5.7 Yes
Application samba samba 3.5.8 Yes
Application samba samba 3.5.9 Yes
Application samba samba 3.5.10 Yes
Application samba samba 3.5.11 Yes
Application samba samba 3.5.12 Yes
Application samba samba 3.5.13 Yes
Application samba samba 3.5.14 Yes
Application samba samba 3.5.15 Yes
Application samba samba 3.5.16 Yes
Application samba samba 3.5.17 Yes
Application samba samba 3.5.18 Yes
Application samba samba 3.5.19 Yes
Application samba samba 3.5.20 Yes
Application samba samba 3.5.21 Yes
Application samba samba 3.5.22 Yes
Application samba samba 3.6.0 Yes
Application samba samba 3.6.1 Yes
Application samba samba 3.6.2 Yes
Application samba samba 3.6.10 Yes
Application samba samba 3.6.11 Yes
Application samba samba 3.6.12 Yes
Application samba samba 3.6.13 Yes
Application samba samba 3.6.14 Yes
Application samba samba 3.6.15 Yes
Application samba samba 3.6.16 Yes
Application samba samba 3.6.17 Yes
Application samba samba 3.6.18 Yes
Application samba samba 3.6.19 Yes
Application samba samba 3.6.20 Yes
Application samba samba 3.6.21 Yes
Application samba samba 3.6.22 Yes
Application samba samba 3.6.23 Yes
Application samba samba 3.6.24 Yes
Application samba samba 4.0.0 Yes
Application samba samba 4.0.1 Yes
Application samba samba 4.0.2 Yes
Application samba samba 4.0.3 Yes
Application samba samba 4.0.4 Yes
Application samba samba 4.0.5 Yes
Application samba samba 4.0.6 Yes
Application samba samba 4.0.7 Yes
Application samba samba 4.0.8 Yes
Application samba samba 4.0.9 Yes
Application samba samba 4.0.10 Yes
Application samba samba 4.0.11 Yes
Application samba samba 4.0.12 Yes
Application samba samba 4.0.13 Yes
Application samba samba 4.0.14 Yes
Application samba samba 4.0.15 Yes
Application samba samba 4.0.16 Yes
Application samba samba 4.0.17 Yes
Application samba samba 4.0.18 Yes
Application samba samba 4.0.19 Yes
Application samba samba 4.0.20 Yes
Application samba samba 4.0.21 Yes
Application samba samba 4.0.22 Yes
Application samba samba 4.0.23 Yes
Application samba samba 4.0.24 Yes
Application samba samba 4.1.0 Yes
Application samba samba 4.1.1 Yes
Application samba samba 4.1.2 Yes
Application samba samba 4.1.3 Yes
Application samba samba 4.1.4 Yes
Application samba samba 4.1.5 Yes
Application samba samba 4.1.6 Yes
Application samba samba 4.1.7 Yes
Application samba samba 4.1.8 Yes
Application samba samba 4.1.9 Yes
Application samba samba 4.1.10 Yes
Application samba samba 4.1.11 Yes
Application samba samba 4.1.12 Yes
Application samba samba 4.1.13 Yes
Application samba samba 4.1.14 Yes
Application samba samba 4.1.15 Yes
Application samba samba 4.1.16 Yes
Application samba samba 4.2.0 Yes
Application samba samba 4.2.0 Yes
Application samba samba 4.2.0 Yes
Application samba samba 4.2.0 Yes
Operating System novell suse_linux_enterprise_desktop 12 Yes
Operating System novell suse_linux_enterprise_server 12 Yes
Operating System novell suse_linux_enterprise_software_development_kit 12 Yes
Operating System canonical ubuntu_linux 12.04 Yes
Operating System canonical ubuntu_linux 14.04 Yes
Operating System canonical ubuntu_linux 14.10 Yes

References