USN-2856-1
Dashboard / Vulnerabilities / USN-2856-1
USN-2856-1
Summary: ldb vulnerabilities
Details: Thilo Uttendorfer discovered that the ldb incorrectly handled certain zero values. A remote attacker could use this issue to cause applications using ldb, such as Samba, to stop responding, resulting in a denial of service. (CVE-2015-3223) Douglas Bagnall discovered that ldb incorrectly handled certain string lengths. A remote attacker could use this issue to possibly access sensitive information from memory of applications using ldb, such as Samba. (CVE-2015-5330)
References: https://ubuntu.com/security/notices/USN-2856-1, https://ubuntu.com/security/CVE-2015-3223, https://ubuntu.com/security/CVE-2015-5330
Affected packages
Package
Name: ldb
Purl: pkg:deb/ubuntu/ldb@1:1.1.16-1ubuntu0.1?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
