PT-2007-5078 · Linux+1 · Linux Kernel+1

Published

2007-08-09

·

Updated

2017-09-29

·

CVE-2007-3843

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Linux kernel versions prior to 2.6.23-rc1
Description: The issue concerns the Linux kernel checking the wrong global variable for the CIFS sec mount option. This could potentially allow remote attackers to spoof CIFS network traffic that the client configured for security signatures. An example of this issue is demonstrated by the lack of signing despite the sec=ntlmv2i option in a SetupAndX request.
Recommendations: For Linux kernel versions prior to 2.6.23-rc1, update to version 2.6.23-rc1 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-3843
DSA-1363-1
RHSA-2007:0705
RHSA-2007:0939
RHSA-2007_0705
RHSA-2007_0939

Affected Products

Linux Kernel
Red Hat