PT-2016-3327 · Samba+5 · Samba+5
Stefan Metzmacher
·
Published
2015-04-01
·
Updated
2024-06-15
·
CVE-2016-2115
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Samba versions 3.x and earlier
Samba versions 4.1.x through 4.2.10
Samba versions 4.3.x through 4.3.7
Samba versions 4.4.x through 4.4.1
Description
The issue is related to the lack of required SMB signing within a DCERPC session over
ncacn np, allowing man-in-the-middle attackers to spoof SMB clients by modifying the client-server data stream. This vulnerability is associated with security shortcomings in the ncacn np function of the Samba network interaction package, which can be exploited by a remote attacker to impact data integrity.Recommendations
For Samba versions 3.x and earlier, update to version 4.2.11 or later.
For Samba versions 4.1.x through 4.2.10, update to version 4.2.11 or later.
For Samba versions 4.3.x through 4.3.7, update to version 4.3.8 or later.
For Samba versions 4.4.x through 4.4.1, update to version 4.4.2 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Centos
Red Hat
Samba
Suse
Ubuntu