Описание
A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent over the wire even if Kerberos authentication was required.
Меры по смягчению последствий
Ensure the following [global] smb.conf parameters are set to their default values as shown below:
Or use the '-k' command line option only without the -U option, which will make use of an existing krb5 ccache.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 6 | samba | Out of support scope | ||
Red Hat Enterprise Linux 6 | samba4 | Out of support scope | ||
Red Hat Enterprise Linux 9 | samba | Not affected | ||
Red Hat Enterprise Linux 7 | samba | Fixed | RHSA-2021:5192 | 16.12.2021 |
Red Hat Enterprise Linux 8 | samba | Fixed | RHSA-2021:5082 | 13.12.2021 |
Red Hat Enterprise Linux 8 | samba | Fixed | RHSA-2021:5082 | 13.12.2021 |
Red Hat Enterprise Linux 8.2 Extended Update Support | samba | Fixed | RHSA-2022:0074 | 11.01.2022 |
Red Hat Enterprise Linux 8.4 Extended Update Support | samba | Fixed | RHSA-2022:0008 | 04.01.2022 |
Red Hat Gluster Storage 3.5 for RHEL 7 | samba | Fixed | RHSA-2021:4844 | 29.11.2021 |
Red Hat Gluster Storage 3.5 for RHEL 8 | samba | Fixed | RHSA-2021:4843 | 29.11.2021 |
Показывать по
Дополнительная информация
Статус:
EPSS
6.8 Medium
CVSS3
Связанные уязвимости
A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent over the wire even if Kerberos authentication was required.
A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent over the wire even if Kerberos authentication was required.
A flaw was found in the way samba implemented SMB1 authentication. An ...
A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent over the wire even if Kerberos authentication was required.
EPSS
6.8 Medium
CVSS3