CVE-2015-3223
Summary
| CVE | CVE-2015-3223 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-12-29 22:59:00 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The ldb_wildcard_compare function in ldb_match.c in ldb before 1.1.24, as used in the AD LDAP server in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, mishandles certain zero values, which allows remote attackers to cause a denial of service (infinite loop) via crafted packets. |
Risk And Classification
Primary CVSS: v3.0 5.3 MEDIUM from [email protected]
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Problem Types: CWE-189 | CWE-399 | n/a
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 5.3 | MEDIUM | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
| 2.0 | [email protected] | Primary | 5 | AV:N/AC:L/Au:N/C:N/I:N/A:P |
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
NoneAvailability
LowCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
PartialAV:N/AC:L/Au:N/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Samba | Samba | 4.0.0 | All | All | All |
| Application | Samba | Samba | 4.0.1 | All | All | All |
| Application | Samba | Samba | 4.0.10 | All | All | All |
| Application | Samba | Samba | 4.0.11 | All | All | All |
| Application | Samba | Samba | 4.0.12 | All | All | All |
| Application | Samba | Samba | 4.0.13 | All | All | All |
| Application | Samba | Samba | 4.0.14 | All | All | All |
| Application | Samba | Samba | 4.0.15 | All | All | All |
| Application | Samba | Samba | 4.0.16 | All | All | All |
| Application | Samba | Samba | 4.0.17 | All | All | All |
| Application | Samba | Samba | 4.0.18 | All | All | All |
| Application | Samba | Samba | 4.0.19 | All | All | All |
| Application | Samba | Samba | 4.0.2 | All | All | All |
| Application | Samba | Samba | 4.0.20 | All | All | All |
| Application | Samba | Samba | 4.0.21 | All | All | All |
| Application | Samba | Samba | 4.0.22 | All | All | All |
| Application | Samba | Samba | 4.0.23 | All | All | All |
| Application | Samba | Samba | 4.0.24 | All | All | All |
| Application | Samba | Samba | 4.0.3 | All | All | All |
| Application | Samba | Samba | 4.0.4 | All | All | All |
| Application | Samba | Samba | 4.0.5 | All | All | All |
| Application | Samba | Samba | 4.0.6 | All | All | All |
| Application | Samba | Samba | 4.0.7 | All | All | All |
| Application | Samba | Samba | 4.0.8 | All | All | All |
| Application | Samba | Samba | 4.0.9 | All | All | All |
| Application | Samba | Samba | 4.1.0 | All | All | All |
| Application | Samba | Samba | 4.1.1 | All | All | All |
| Application | Samba | Samba | 4.1.10 | All | All | All |
| Application | Samba | Samba | 4.1.11 | All | All | All |
| Application | Samba | Samba | 4.1.12 | All | All | All |
| Application | Samba | Samba | 4.1.13 | All | All | All |
| Application | Samba | Samba | 4.1.14 | All | All | All |
| Application | Samba | Samba | 4.1.15 | All | All | All |
| Application | Samba | Samba | 4.1.16 | All | All | All |
| Application | Samba | Samba | 4.1.17 | All | All | All |
| Application | Samba | Samba | 4.1.18 | All | All | All |
| Application | Samba | Samba | 4.1.19 | All | All | All |
| Application | Samba | Samba | 4.1.2 | All | All | All |
| Application | Samba | Samba | 4.1.20 | All | All | All |
| Application | Samba | Samba | 4.1.21 | All | All | All |
| Application | Samba | Samba | 4.1.3 | All | All | All |
| Application | Samba | Samba | 4.1.4 | All | All | All |
| Application | Samba | Samba | 4.1.5 | All | All | All |
| Application | Samba | Samba | 4.1.6 | All | All | All |
| Application | Samba | Samba | 4.1.7 | All | All | All |
| Application | Samba | Samba | 4.1.8 | All | All | All |
| Application | Samba | Samba | 4.1.9 | All | All | All |
| Application | Samba | Samba | 4.2.0 | All | All | All |
| Application | Samba | Samba | 4.2.1 | All | All | All |
| Application | Samba | Samba | 4.2.2 | All | All | All |
| Application | Samba | Samba | 4.2.3 | All | All | All |
| Application | Samba | Samba | 4.2.4 | All | All | All |
| Application | Samba | Samba | 4.2.5 | All | All | All |
| Application | Samba | Samba | 4.2.6 | All | All | All |
| Application | Samba | Samba | 4.3.0 | All | All | All |
| Application | Samba | Samba | 4.3.1 | All | All | All |
| Application | Samba | Samba | 4.3.2 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [security-announce] SUSE-SU-2015:2304-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| git.samba.org - samba.git/commit | af854a3a-2127-422b-91ae-364da2661108 | git.samba.org | |
| USN-2855-1: Samba vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| [security-announce] openSUSE-SU-2015:2354-1: important: Security update | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| [security-announce] openSUSE-SU-2016:1064-1: important: Security update | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Debian -- Security Information -- DSA-3433-1 samba | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| [SECURITY] Fedora 22 Update: samba-4.2.7-0.fc22 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| USN-2855-2: Samba regression | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| Samba: Multiple vulnerabilities (GLSA 201612-47) — Gentoo security | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| Samba Multiple Flaws Let Remote Users Access Data and Files, Obtain Potentially Sensitive Information, and Deny Service - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Samba ldb 'ldb_wildcard_compare()' Function Denial of Service Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Oracle Linux Bulletin - January 2016 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | |
| USN-2856-1: ldb vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| [security-announce] openSUSE-SU-2015:2356-1: important: Security update | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| [security-announce] SUSE-SU-2015:2305-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Bug 1290287 – CVE-2015-3223 libldb: Remote DoS in Samba (AD) LDAP server | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| git.samba.org - samba.git/commit | af854a3a-2127-422b-91ae-364da2661108 | git.samba.org | |
| Samba - Security Announcement Archive | af854a3a-2127-422b-91ae-364da2661108 | www.samba.org | Vendor Advisory |
| [SECURITY] Fedora 23 Update: samba-4.3.3-0.fc23 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| git.samba.org - samba.git/commit | MITRE | git.samba.org | |
| git.samba.org - samba.git/commit | MITRE | git.samba.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.