Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-2119

Опубликовано: 07 июл. 2016
Источник: redhat
CVSS3: 7.5
CVSS2: 5.4
EPSS Низкий

Описание

libcli/smb/smbXcli_base.c in Samba 4.x before 4.2.14, 4.3.x before 4.3.11, and 4.4.x before 4.4.5 allows man-in-the-middle attackers to bypass a client-signing protection mechanism, and consequently spoof SMB2 and SMB3 servers, via the (1) SMB2_SESSION_FLAG_IS_GUEST or (2) SMB2_SESSION_FLAG_IS_NULL flag.

A flaw was found in the way Samba initiated signed DCE/RPC connections. A man-in-the-middle attacker could use this flaw to downgrade the connection to not use signing and therefore impersonate the server.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5sambaNot affected
Red Hat Enterprise Linux 6sambaNot affected
Red Hat Enterprise Linux 6samba4FixedRHSA-2016:148726.07.2016
Red Hat Enterprise Linux 7sambaFixedRHSA-2016:148626.07.2016
Red Hat Gluster Storage 3.1 for RHEL 6sambaFixedRHSA-2016:149426.07.2016
Red Hat Gluster Storage 3.1 for RHEL 7sambaFixedRHSA-2016:149426.07.2016

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1351955samba: Client side SMB2/3 required signing can be downgraded

EPSS

Процентиль: 78%
0.01162
Низкий

7.5 High

CVSS3

5.4 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 9 лет назад

libcli/smb/smbXcli_base.c in Samba 4.x before 4.2.14, 4.3.x before 4.3.11, and 4.4.x before 4.4.5 allows man-in-the-middle attackers to bypass a client-signing protection mechanism, and consequently spoof SMB2 and SMB3 servers, via the (1) SMB2_SESSION_FLAG_IS_GUEST or (2) SMB2_SESSION_FLAG_IS_NULL flag.

CVSS3: 7.5
nvd
около 9 лет назад

libcli/smb/smbXcli_base.c in Samba 4.x before 4.2.14, 4.3.x before 4.3.11, and 4.4.x before 4.4.5 allows man-in-the-middle attackers to bypass a client-signing protection mechanism, and consequently spoof SMB2 and SMB3 servers, via the (1) SMB2_SESSION_FLAG_IS_GUEST or (2) SMB2_SESSION_FLAG_IS_NULL flag.

CVSS3: 7.5
debian
около 9 лет назад

libcli/smb/smbXcli_base.c in Samba 4.x before 4.2.14, 4.3.x before 4.3 ...

suse-cvrf
почти 9 лет назад

Security update for samba

suse-cvrf
почти 9 лет назад

Security update for samba

EPSS

Процентиль: 78%
0.01162
Низкий

7.5 High

CVSS3

5.4 Medium

CVSS2