Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-12150

Опубликовано: 20 сент. 2017
Источник: redhat
CVSS3: 7.4

Описание

It was found that samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8 did not enforce "SMB signing" when certain configuration options were enabled. A remote attacker could launch a man-in-the-middle attack and retrieve information in plain-text.

It was found that samba did not enforce "SMB signing" when certain configuration options were enabled. A remote attacker could launch a man-in-the-middle attack and retrieve information in plain-text.

Меры по смягчению последствий

The missing implied signing for 'smb2mount -e', 'smbcacls -e' and 'smbcquotas -e' can be enforced by explicitly using '--signing=required' on the commandline or "client signing = required" in smb.conf.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5sambaWill not fix
Red Hat Enterprise Linux 5samba3xWill not fix
Red Hat Enterprise Linux 6sambaFixedRHSA-2017:278921.09.2017
Red Hat Enterprise Linux 6samba4FixedRHSA-2017:279121.09.2017
Red Hat Enterprise Linux 7sambaFixedRHSA-2017:279021.09.2017
Red Hat Gluster Storage 3.3 for RHEL 6sambaFixedRHSA-2017:285804.10.2017
Red Hat Gluster Storage 3.3 for RHEL 7sambaFixedRHSA-2017:285804.10.2017

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-300
https://bugzilla.redhat.com/show_bug.cgi?id=1488400samba: Some code path don't enforce smb signing, when they should

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 7.4
ubuntu
почти 7 лет назад

It was found that samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8 did not enforce "SMB signing" when certain configuration options were enabled. A remote attacker could launch a man-in-the-middle attack and retrieve information in plain-text.

CVSS3: 7.4
nvd
почти 7 лет назад

It was found that samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8 did not enforce "SMB signing" when certain configuration options were enabled. A remote attacker could launch a man-in-the-middle attack and retrieve information in plain-text.

CVSS3: 7.4
msrc
9 месяцев назад

Описание отсутствует

CVSS3: 7.4
debian
почти 7 лет назад

It was found that samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x ...

CVSS3: 7.4
github
около 3 лет назад

It was found that samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8 did not enforce "SMB signing" when certain configuration options were enabled. A remote attacker could launch a man-in-the-middle attack and retrieve information in plain-text.

7.4 High

CVSS3