CVE-2015-0240
Summary
| CVE | CVE-2015-0240 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-02-24 01:59:00 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc5 performs a free operation on an uninitialized stack pointer, which allows remote attackers to execute arbitrary code via crafted Netlogon packets that use the ServerPasswordSet RPC API, as demonstrated by packets reaching the _netr_ServerPasswordSet function in rpc_server/netlogon/srv_netlog_nt.c. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Canonical | Ubuntu Linux | 12.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 14.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 14.10 | All | All | All |
| Operating System | Novell | Suse Linux Enterprise Desktop | 12 | All | All | All |
| Operating System | Novell | Suse Linux Enterprise Server | 12 | All | All | All |
| Operating System | Novell | Suse Linux Enterprise Software Development Kit | 12 | All | All | All |
| Operating System | Redhat | Enterprise Linux | 5 | All | All | All |
| Operating System | Redhat | Enterprise Linux | 6.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux | 7.0 | All | All | All |
| Application | Samba | Samba | 3.5.0 | All | All | All |
| Application | Samba | Samba | 3.5.1 | All | All | All |
| Application | Samba | Samba | 3.5.10 | All | All | All |
| Application | Samba | Samba | 3.5.11 | All | All | All |
| Application | Samba | Samba | 3.5.12 | All | All | All |
| Application | Samba | Samba | 3.5.13 | All | All | All |
| Application | Samba | Samba | 3.5.14 | All | All | All |
| Application | Samba | Samba | 3.5.15 | All | All | All |
| Application | Samba | Samba | 3.5.16 | All | All | All |
| Application | Samba | Samba | 3.5.17 | All | All | All |
| Application | Samba | Samba | 3.5.18 | All | All | All |
| Application | Samba | Samba | 3.5.19 | All | All | All |
| Application | Samba | Samba | 3.5.2 | All | All | All |
| Application | Samba | Samba | 3.5.20 | All | All | All |
| Application | Samba | Samba | 3.5.21 | All | All | All |
| Application | Samba | Samba | 3.5.22 | All | All | All |
| Application | Samba | Samba | 3.5.3 | All | All | All |
| Application | Samba | Samba | 3.5.4 | All | All | All |
| Application | Samba | Samba | 3.5.5 | All | All | All |
| Application | Samba | Samba | 3.5.6 | All | All | All |
| Application | Samba | Samba | 3.5.7 | All | All | All |
| Application | Samba | Samba | 3.5.8 | All | All | All |
| Application | Samba | Samba | 3.5.9 | All | All | All |
| Application | Samba | Samba | 3.6.0 | All | All | All |
| Application | Samba | Samba | 3.6.1 | All | All | All |
| Application | Samba | Samba | 3.6.10 | All | All | All |
| Application | Samba | Samba | 3.6.11 | All | All | All |
| Application | Samba | Samba | 3.6.12 | All | All | All |
| Application | Samba | Samba | 3.6.13 | All | All | All |
| Application | Samba | Samba | 3.6.14 | All | All | All |
| Application | Samba | Samba | 3.6.15 | All | All | All |
| Application | Samba | Samba | 3.6.16 | All | All | All |
| Application | Samba | Samba | 3.6.17 | All | All | All |
| Application | Samba | Samba | 3.6.18 | All | All | All |
| Application | Samba | Samba | 3.6.19 | All | All | All |
| Application | Samba | Samba | 3.6.2 | All | All | All |
| Application | Samba | Samba | 3.6.20 | All | All | All |
| Application | Samba | Samba | 3.6.21 | All | All | All |
| Application | Samba | Samba | 3.6.22 | All | All | All |
| Application | Samba | Samba | 3.6.23 | All | All | All |
| Application | Samba | Samba | 3.6.24 | All | All | All |
| Application | Samba | Samba | 4.0.0 | All | All | All |
| Application | Samba | Samba | 4.0.1 | All | All | All |
| Application | Samba | Samba | 4.0.10 | All | All | All |
| Application | Samba | Samba | 4.0.11 | All | All | All |
| Application | Samba | Samba | 4.0.12 | All | All | All |
| Application | Samba | Samba | 4.0.13 | All | All | All |
| Application | Samba | Samba | 4.0.14 | All | All | All |
| Application | Samba | Samba | 4.0.15 | All | All | All |
| Application | Samba | Samba | 4.0.16 | All | All | All |
| Application | Samba | Samba | 4.0.17 | All | All | All |
| Application | Samba | Samba | 4.0.18 | All | All | All |
| Application | Samba | Samba | 4.0.19 | All | All | All |
| Application | Samba | Samba | 4.0.2 | All | All | All |
| Application | Samba | Samba | 4.0.20 | All | All | All |
| Application | Samba | Samba | 4.0.21 | All | All | All |
| Application | Samba | Samba | 4.0.22 | All | All | All |
| Application | Samba | Samba | 4.0.23 | All | All | All |
| Application | Samba | Samba | 4.0.24 | All | All | All |
| Application | Samba | Samba | 4.0.3 | All | All | All |
| Application | Samba | Samba | 4.0.4 | All | All | All |
| Application | Samba | Samba | 4.0.5 | All | All | All |
| Application | Samba | Samba | 4.0.6 | All | All | All |
| Application | Samba | Samba | 4.0.7 | All | All | All |
| Application | Samba | Samba | 4.0.8 | All | All | All |
| Application | Samba | Samba | 4.0.9 | All | All | All |
| Application | Samba | Samba | 4.1.0 | All | All | All |
| Application | Samba | Samba | 4.1.1 | All | All | All |
| Application | Samba | Samba | 4.1.10 | All | All | All |
| Application | Samba | Samba | 4.1.11 | All | All | All |
| Application | Samba | Samba | 4.1.12 | All | All | All |
| Application | Samba | Samba | 4.1.13 | All | All | All |
| Application | Samba | Samba | 4.1.14 | All | All | All |
| Application | Samba | Samba | 4.1.15 | All | All | All |
| Application | Samba | Samba | 4.1.16 | All | All | All |
| Application | Samba | Samba | 4.1.2 | All | All | All |
| Application | Samba | Samba | 4.1.3 | All | All | All |
| Application | Samba | Samba | 4.1.4 | All | All | All |
| Application | Samba | Samba | 4.1.5 | All | All | All |
| Application | Samba | Samba | 4.1.6 | All | All | All |
| Application | Samba | Samba | 4.1.7 | All | All | All |
| Application | Samba | Samba | 4.1.8 | All | All | All |
| Application | Samba | Samba | 4.1.9 | All | All | All |
| Application | Samba | Samba | 4.2.0 | rc1 | All | All |
| Application | Samba | Samba | 4.2.0 | rc2 | All | All |
| Application | Samba | Samba | 4.2.0 | rc3 | All | All |
| Application | Samba | Samba | 4.2.0 | rc4 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Samba: Multiple vulnerabilities (GLSA 201502-15) — Gentoo security | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| USN-2508-1: Samba vulnerability | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Samba vulnerability (CVE-2015-0240) - Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | |
| [security-announce] SUSE-SU-2015:0386-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| [security-announce] openSUSE-SU-2016:1064-1: important: Security update | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Support / Security / Advisories / / MDVSA-2015:082 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| Oracle Bulletin Board Update - January 2015 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | |
| Mageia Advisory: MGASA-2015-0084 - Updated samba packages fix CVE-2015-0240 | af854a3a-2127-422b-91ae-364da2661108 | advisories.mageia.org | |
| Samba vulnerability (CVE-2015-0240) | Red Hat Security | af854a3a-2127-422b-91ae-364da2661108 | securityblog.redhat.com | Exploit |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| '[security bulletin] HPSBUX03320 SSRT101952 rev.1 - HP-UX CIFS Server (Samba), Remote Denial of Servi' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| [security-announce] openSUSE-SU-2015:0375-1: important: Security update | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| The Slackware Linux Project: Slackware Security Advisories | af854a3a-2127-422b-91ae-364da2661108 | www.slackware.com | |
| [security-announce] SUSE-SU-2015:0371-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Debian -- Security Information -- DSA-3171-1 samba | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Samba 'TALLOC_FREE()' Function Remote Code Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Samba smbd Memory Free Error Lets Remote Users Execute Arbitrary Code with Root Privileges - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Support / Security / Advisories / / MDVSA-2015:081 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| '[security bulletin] HPSBGN03288 rev.1 - HP Server Automation, Remote Arbitrary Code Execution' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Samba < 3.6.2 (x86) - Denial of Service (PoC) - Linux_x86 dos Exploit | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | |
| [security-announce] openSUSE-SU-2016:1107-1: important: Security update | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Samba Remote Code Execution Vulnerability - Lenovo Support US | af854a3a-2127-422b-91ae-364da2661108 | support.lenovo.com | |
| Samba - Security Announcement Archive | af854a3a-2127-422b-91ae-364da2661108 | www.samba.org | Vendor Advisory |
| Samba Remote Code Execution Vulnerability - Lenovo Support (US) | af854a3a-2127-422b-91ae-364da2661108 | support.lenovo.com | |
| security.netapp.com/advisory/ntap-20250509-0001 | af854a3a-2127-422b-91ae-364da2661108 | security.netapp.com | |
| [security-announce] openSUSE-SU-2016:1106-1: important: Security update | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| 1191325 – (CVE-2015-0240) CVE-2015-0240 samba: talloc free on uninitialized stack pointer in netlogon server could lead to remote-code execution | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| [security-announce] SUSE-SU-2015:0353-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Red Hat Customer Portal | MITRE | access.redhat.com | |
| Red Hat Customer Portal | MITRE | access.redhat.com | |
| Red Hat Customer Portal | MITRE | access.redhat.com | |
| Red Hat Customer Portal | MITRE | access.redhat.com | |
| Red Hat Customer Portal | MITRE | access.redhat.com | |
| Red Hat Customer Portal | MITRE | access.redhat.com | |
| Red Hat Customer Portal | MITRE | access.redhat.com | |
| Red Hat Customer Portal | MITRE | access.redhat.com | |
| Red Hat Customer Portal | MITRE | access.redhat.com | |
| CVE-2015-0240 - Red Hat Customer Portal | MITRE | access.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.