Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2015-7540

Description

The LDAP server in the AD domain controller in Samba 4.x before 4.1.22 does not check return values to ensure successful ASN.1 memory allocation, which allows remote attackers to cause a denial of service (memory consumption and daemon crash) via crafted packets.

POC

Reference

- http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html

Github

- https://github.com/ARPSyndicate/cve-scores

- https://github.com/Live-Hack-CVE/CVE-2015-7540