Samba 'TALLOC_FREE()' Function Remote Code Execution Vulnerability
BID:72711
Info
Samba 'TALLOC_FREE()' Function Remote Code Execution Vulnerability
| Bugtraq ID: | 72711 |
| Class: | Unknown |
| CVE: |
CVE-2015-0240 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 23 2015 12:00AM |
| Updated: | Jul 06 2016 02:29PM |
| Credit: | Richard van Eeden of Microsoft Vulnerability Research |
| Vulnerable: |
Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Samba Samba 3.6.4 Samba Samba 3.6.3 Samba Samba 3.6.2 Samba Samba 3.6.1 Samba Samba 3.6 Samba Samba 3.5.9 Samba Samba 3.5.8 Samba Samba 3.5.2 Samba Samba 3.5.1 Samba Samba 3.5 Samba Samba 3.6.5 Samba Samba 3.5.7 Samba Samba 3.5.6 Samba Samba 3.5.5 Samba Samba 3.5.4 Samba Samba 3.5.3 Samba Samba 3.5.15 Samba Samba 3.5.14 Samba Samba 3.5.11 Samba Samba 3.5.10 RedHat Enterprise Linux Desktop Workstation 5 client Red Hat Enterprise Linux Workstation 6 Red Hat Enterprise Linux Server 6 Red Hat Enterprise Linux Long Life 5.6 server Red Hat Enterprise Linux HPC Node 6 Red Hat Enterprise Linux Desktop 6 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux 5 Server Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 Oracle Enterprise Linux 5 IBM Storwize V7000 Unified 1.3.1.0 IBM Storwize V7000 Unified 1.3.0.5 IBM Storwize V7000 Unified 1.3.0.0 IBM Scale Out Network Attached Storage 1.3.0.5 IBM Scale Out Network Attached Storage 1.3.0.4 HP HP-UX B.11.31 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 CentOS CentOS 6 CentOS CentOS 5 |
| Not Vulnerable: | |
Exploit / POC
Samba 'TALLOC_FREE()' Function Remote Code Execution Vulnerability
The following exploit and prof-of-concept code are available:
The following exploit and prof-of-concept code are available: