Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-2115

Опубликовано: 12 апр. 2016
Источник: redhat
CVSS2: 5.8
EPSS Средний

Описание

Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not require SMB signing within a DCERPC session over ncacn_np, which allows man-in-the-middle attackers to spoof SMB clients by modifying the client-server data stream.

It was found that Samba did not enable integrity protection for IPC traffic by default. A man-in-the-middle attacker could use this flaw to view and modify the data sent between a Samba server and a client.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4sambaAffected
Red Hat Enterprise Linux 5sambaAffected
Red Hat Enterprise Linux Extended Update Support 5.6sambaAffected
Red Hat Enterprise Linux Extended Update Support 5.6samba3xAffected
Red Hat Enterprise Linux Extended Update Support 5.9sambaAffected
Red Hat Enterprise Linux 5samba3xFixedRHSA-2016:061312.04.2016
Red Hat Enterprise Linux 5.6 Long Lifesamba3xFixedRHSA-2016:062412.04.2016
Red Hat Enterprise Linux 5.9 Long Lifesamba3xFixedRHSA-2016:062412.04.2016
Red Hat Enterprise Linux 6sambaFixedRHSA-2016:061112.04.2016
Red Hat Enterprise Linux 6ipaFixedRHSA-2016:061213.04.2016

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-300
https://bugzilla.redhat.com/show_bug.cgi?id=1312084samba: Smb signing not required by default when smb client connection is used for ipc usage

EPSS

Процентиль: 96%
0.23265
Средний

5.8 Medium

CVSS2

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 9 лет назад

Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not require SMB signing within a DCERPC session over ncacn_np, which allows man-in-the-middle attackers to spoof SMB clients by modifying the client-server data stream.

CVSS3: 5.9
nvd
больше 9 лет назад

Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not require SMB signing within a DCERPC session over ncacn_np, which allows man-in-the-middle attackers to spoof SMB clients by modifying the client-server data stream.

CVSS3: 5.9
debian
больше 9 лет назад

Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before ...

CVSS3: 5.9
github
больше 3 лет назад

Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not require SMB signing within a DCERPC session over ncacn_np, which allows man-in-the-middle attackers to spoof SMB clients by modifying the client-server data stream.

CVSS3: 5.9
fstec
больше 9 лет назад

Уязвимость функции ncacn_np пакета программ сетевого взаимодействия Samba, связанная с недостатками элементов безопасности, позволяющая нарушителю оказать воздействие на целостность данных

EPSS

Процентиль: 96%
0.23265
Средний

5.8 Medium

CVSS2