Bug 1290287 (CVE-2015-3223)
Summary: | CVE-2015-3223 libldb: Remote DoS in Samba (AD) LDAP server | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Huzaifa S. Sidhpurwala <huzaifas> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | aavati, asn, carnil, gdeschner, jarrpa, jrusnack, nlevinki, rfortier, sbose, security-response-team, sgirijan, sisharma, slong, smohan, ssaha, vbellur |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | libldb 1.1.24 | Doc Type: | Bug Fix |
Doc Text: |
A denial of service flaw was found in the ldb_wildcard_compare() function of libldb. A remote attacker could send a specially crafted packet that, when processed by an application using libldb (for example the AD LDAP server in Samba), would cause that application to consume an excessive amount of memory and crash.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2016-01-08 12:18:43 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1290708, 1290709, 1290710, 1290712, 1290713, 1290714, 1290715, 1291376, 1292069 | ||
Bug Blocks: | 1281327 |
Description
Huzaifa S. Sidhpurwala
2015-12-10 04:52:49 UTC
Acknowledgements: Red Hat would like to thank the Samba project for reporting this issue. Upstream acknowledges Thilo Uttendorfer as the original reporter. Created samba tracking bugs for this issue: Affects: fedora-all [bug 1292069] External References: https://www.samba.org/samba/security/CVE-2015-3223.html Upstream commits tagged with CVE-2015-3223. Both are changes in libldb rather than samba. https://git.samba.org/?p=samba.git;a=commitdiff;h=ec504dbf69636a554add1f3d5703dd6c3ad450b8 https://git.samba.org/?p=samba.git;a=commitdiff;h=aa6c27148b9d3f8c1e4fdd5dd46bfecbbd0ca465 This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Red Hat Enterprise Linux 6 Via RHSA-2016:0009 https://rhn.redhat.com/errata/RHSA-2016-0009.html This issue has been addressed in the following products: Red Hat Gluster Storage 3.1 for RHEL 6 Red Hat Gluster Storage 3.1 for RHEL 7 Via RHSA-2016:0014 https://rhn.redhat.com/errata/RHSA-2016-0014.html |