PT-2015-3397 · Samba Team+6 · Samba+5

Stefan Metzmacher

·

Published

2015-12-16

·

Updated

2024-06-15

·

CVE-2015-5296

CVSS v3.1

5.4

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Samba versions 3.x and 4.x before 4.1.22 Samba versions 4.2.x before 4.2.7 Samba versions 4.3.x before 4.3.3
Description The issue is related to a lack of input validation in the Samba package, specifically in components clidfs.c, libsmb server.c, and smbXcli base.c. This allows a remote attacker to impact data integrity. The vulnerability is also related to Samba supporting connections that are encrypted but unsigned, which enables man-in-the-middle attackers to conduct encrypted-to-unencrypted downgrade attacks by modifying the client-server data stream.
Recommendations For Samba versions 3.x and 4.x before 4.1.22, update to version 4.1.22 or later to resolve the issue. For Samba versions 4.2.x before 4.2.7, update to version 4.2.7 or later to resolve the issue. For Samba versions 4.3.x before 4.3.3, update to version 4.3.3 or later to resolve the issue. As a temporary workaround, consider disabling the use of encrypted but unsigned connections to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-2138
ALT-PU-2015-2139
BDU:2021-01298
CESA-2016_0006
CESA-2016_0010
CESA-2016_0011
CVE-2015-5296
DLA-379-1
DSA-3433-1
ECHO-F063-8083-52BC
MGASA-2016-0094
OPENSUSE-SU-2015_2354-1
OPENSUSE-SU-2015_2356-1
OPENSUSE-SU-2016_1064-1
OPENSUSE-SU-2016_1106-1
OPENSUSE-SU-2024:10069-1
RHSA-2016:0006
RHSA-2016:0010
RHSA-2016:0011
RHSA-2016:0015
RHSA-2016:0016
RHSA-2016_0006
RHSA-2016_0010
RHSA-2016_0011
SUSE-SU-2015:2304-1
SUSE-SU-2015:2305-1
SUSE-SU-2016:0032-1
SUSE-SU-2016:0164-1
USN-2855-1
USN-2855-2

Affected Products

Alt Linux
Centos
Red Hat
Samba
Suse
Ubuntu