PT-2007-5078 · Linux+1 · Linux Kernel+1
Published
2007-08-09
·
Updated
2017-09-29
·
CVE-2007-3843
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
Linux kernel versions prior to 2.6.23-rc1
Description:
The issue concerns the Linux kernel checking the wrong global variable for the CIFS sec mount option. This could potentially allow remote attackers to spoof CIFS network traffic that the client configured for security signatures. An example of this issue is demonstrated by the lack of signing despite the sec=ntlmv2i option in a SetupAndX request.
Recommendations:
For Linux kernel versions prior to 2.6.23-rc1, update to version 2.6.23-rc1 or later to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel
Red Hat