Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-2115

Опубликовано: 12 апр. 2016
Источник: redhat
CVSS2: 5.8
EPSS Средний

Описание

Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not require SMB signing within a DCERPC session over ncacn_np, which allows man-in-the-middle attackers to spoof SMB clients by modifying the client-server data stream.

It was found that Samba did not enable integrity protection for IPC traffic by default. A man-in-the-middle attacker could use this flaw to view and modify the data sent between a Samba server and a client.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4sambaAffected
Red Hat Enterprise Linux 5sambaAffected
Red Hat Enterprise Linux 5samba3xFixedRHSA-2016:061312.04.2016
Red Hat Enterprise Linux 5.6 Long Lifesamba3xFixedRHSA-2016:062412.04.2016
Red Hat Enterprise Linux 5.9 Long Lifesamba3xFixedRHSA-2016:062412.04.2016
Red Hat Enterprise Linux 6sambaFixedRHSA-2016:061112.04.2016
Red Hat Enterprise Linux 6ipaFixedRHSA-2016:061213.04.2016
Red Hat Enterprise Linux 6libldbFixedRHSA-2016:061213.04.2016
Red Hat Enterprise Linux 6libtallocFixedRHSA-2016:061213.04.2016
Red Hat Enterprise Linux 6libtdbFixedRHSA-2016:061213.04.2016

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-300
https://bugzilla.redhat.com/show_bug.cgi?id=1312084samba: Smb signing not required by default when smb client connection is used for ipc usage

EPSS

Процентиль: 95%
0.10232
Средний

5.8 Medium

CVSS2

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 10 лет назад

Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not require SMB signing within a DCERPC session over ncacn_np, which allows man-in-the-middle attackers to spoof SMB clients by modifying the client-server data stream.

CVSS3: 5.9
nvd
больше 10 лет назад

Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not require SMB signing within a DCERPC session over ncacn_np, which allows man-in-the-middle attackers to spoof SMB clients by modifying the client-server data stream.

CVSS3: 5.9
debian
больше 10 лет назад

Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before ...

CVSS3: 5.9
github
около 4 лет назад

Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not require SMB signing within a DCERPC session over ncacn_np, which allows man-in-the-middle attackers to spoof SMB clients by modifying the client-server data stream.

CVSS3: 5.9
fstec
больше 10 лет назад

Уязвимость функции ncacn_np пакета программ сетевого взаимодействия Samba, связанная с недостатками элементов безопасности, позволяющая нарушителю оказать воздействие на целостность данных

EPSS

Процентиль: 95%
0.10232
Средний

5.8 Medium

CVSS2