PT-2007-5078 · Linux+1 · Linux Kernel+1

Publicado

2007-08-09

·

Atualizado

2017-09-29

·

CVE-2007-3843

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Linux kernel versions prior to 2.6.23-rc1
Description: The issue concerns the Linux kernel checking the wrong global variable for the CIFS sec mount option. This could potentially allow remote attackers to spoof CIFS network traffic that the client configured for security signatures. An example of this issue is demonstrated by the lack of signing despite the sec=ntlmv2i option in a SetupAndX request.
Recommendations: For Linux kernel versions prior to 2.6.23-rc1, update to version 2.6.23-rc1 or later to resolve the issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-3843
DSA-1363-1
RHSA-2007:0705
RHSA-2007:0939
RHSA-2007_0705
RHSA-2007_0939

Produtos afetados

Linux Kernel
Red Hat