Medium severity5.9NVD Advisory· Published Apr 25, 2016· Updated May 6, 2026
CVE-2015-5370
CVE-2015-5370
Description
Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not properly implement the DCE-RPC layer, which allows remote attackers to perform protocol-downgrade attacks, cause a denial of service (application crash or CPU consumption), or possibly execute arbitrary code on a client system via unspecified vectors.
Affected products
29- osv-coords29 versionspkg:rpm/opensuse/samba&distro=openSUSE%20Tumbleweedpkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Desktop%2012pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP1pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2012pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2012%20SP1pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP2-LTSSpkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-LTSSpkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-TERADATApkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%2012pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP3pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012pkg:rpm/suse/samba&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP1pkg:rpm/suse/samba&distro=SUSE%20Manager%202.1pkg:rpm/suse/samba&distro=SUSE%20Manager%20Proxy%202.1pkg:rpm/suse/samba&distro=SUSE%20OpenStack%20Cloud%205pkg:rpm/suse/samba-doc&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP2-LTSSpkg:rpm/suse/samba-doc&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-LTSSpkg:rpm/suse/samba-doc&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-TERADATApkg:rpm/suse/samba-doc&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4pkg:rpm/suse/samba-doc&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4pkg:rpm/suse/samba-doc&distro=SUSE%20Manager%202.1pkg:rpm/suse/samba-doc&distro=SUSE%20Manager%20Proxy%202.1pkg:rpm/suse/samba-doc&distro=SUSE%20OpenStack%20Cloud%205
< 4.5.0-1.1+ 28 more
- (no CPE)range: < 4.5.0-1.1
- (no CPE)range: < 4.2.4-18.17.1
- (no CPE)range: < 4.2.4-16.1
- (no CPE)range: < 4.2.4-18.17.1
- (no CPE)range: < 4.2.4-16.1
- (no CPE)range: < 3.6.3-52.1
- (no CPE)range: < 3.6.3-76.1
- (no CPE)range: < 3.6.3-76.1
- (no CPE)range: < 3.6.3-76.1
- (no CPE)range: < 4.2.4-18.17.1
- (no CPE)range: < 4.2.4-16.1
- (no CPE)range: < 3.6.3-76.1
- (no CPE)range: < 4.2.4-18.17.1
- (no CPE)range: < 4.2.4-16.1
- (no CPE)range: < 3.6.3-76.1
- (no CPE)range: < 3.6.3-76.1
- (no CPE)range: < 4.2.4-18.17.1
- (no CPE)range: < 4.2.4-16.1
- (no CPE)range: < 3.6.3-76.1
- (no CPE)range: < 3.6.3-76.1
- (no CPE)range: < 3.6.3-76.1
- (no CPE)range: < 3.6.3-52.1
- (no CPE)range: < 3.6.3-76.2
- (no CPE)range: < 3.6.3-76.2
- (no CPE)range: < 3.6.3-76.2
- (no CPE)range: < 3.6.3-76.2
- (no CPE)range: < 3.6.3-76.2
- (no CPE)range: < 3.6.3-76.2
- (no CPE)range: < 3.6.3-76.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
34- www.samba.org/samba/security/CVE-2015-5370.htmlnvdPatchVendor Advisory
- badlock.orgnvd
- lists.fedoraproject.org/pipermail/package-announce/2016-April/182185.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2016-April/182272.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2016-April/182288.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2016-04/msg00020.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2016-04/msg00021.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2016-04/msg00022.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2016-04/msg00023.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2016-04/msg00024.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2016-04/msg00042.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2016-04/msg00047.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2016-04/msg00048.htmlnvd
- rhn.redhat.com/errata/RHSA-2016-0611.htmlnvd
- rhn.redhat.com/errata/RHSA-2016-0612.htmlnvd
- rhn.redhat.com/errata/RHSA-2016-0613.htmlnvd
- rhn.redhat.com/errata/RHSA-2016-0614.htmlnvd
- rhn.redhat.com/errata/RHSA-2016-0618.htmlnvd
- rhn.redhat.com/errata/RHSA-2016-0619.htmlnvd
- rhn.redhat.com/errata/RHSA-2016-0620.htmlnvd
- rhn.redhat.com/errata/RHSA-2016-0624.htmlnvd
- www.debian.org/security/2016/dsa-3548nvd
- www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlnvd
- www.securitytracker.com/id/1035533nvd
- www.slackware.com/security/viewer.phpnvd
- www.ubuntu.com/usn/USN-2950-1nvd
- www.ubuntu.com/usn/USN-2950-2nvd
- www.ubuntu.com/usn/USN-2950-3nvd
- www.ubuntu.com/usn/USN-2950-4nvd
- www.ubuntu.com/usn/USN-2950-5nvd
- bto.bluecoat.com/security-advisory/sa122nvd
- h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplaynvd
- www.samba.org/samba/history/samba-4.2.10.htmlnvd
- www.samba.org/samba/latest_news.htmlnvd
News mentions
0No linked articles in our index yet.