CVE-2015-5370

Public on 2016-04-13
Modified on 2016-04-13
Description
Multiple flaws were found in Samba's DCE/RPC protocol implementation. A remote, authenticated attacker could use these flaws to cause a denial of service against the Samba server (high CPU load or a crash) or, possibly, execute arbitrary code with the permissions of the user running Samba (root). This flaw could also be used to downgrade a secure DCE/RPC connection by a man-in-the-middle attacker taking control of an Active Directory (AD) object and compromising the security of a Samba Active Directory Domain Controller (DC).
Severity
Critical severity
Critical
See what this means
CVSS v3 Base Score
8.5
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 1 samba 2016-04-13 ALAS-2016-686 Fixed

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv2 8.5 AV:N/AC:M/Au:S/C:C/I:C/A:C
NVD CVSSv2 4.3 AV:N/AC:M/Au:N/C:N/I:P/A:N
NVD CVSSv3 5.9 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N