vulnerability

Red Hat: CVE-2016-2119: Moderate: samba4 security update ((Multiple Advisories))

Severity
7
CVSS
(AV:N/AC:M/Au:N/C:P/I:P/A:P)
Published
Jul 7, 2016
Added
Jul 29, 2016
Modified
Jan 17, 2018

Description

libcli/smb/smbXcli_base.c in Samba 4.x before 4.2.14, 4.3.x before 4.3.11, and 4.4.x before 4.4.5 allows man-in-the-middle attackers to bypass a client-signing protection mechanism, and consequently spoof SMB2 and SMB3 servers, via the (1) SMB2_SESSION_FLAG_IS_GUEST or (2) SMB2_SESSION_FLAG_IS_NULL flag.

Solutions

redhat-upgrade-libsmbclientredhat-upgrade-libsmbclient-develredhat-upgrade-libwbclientredhat-upgrade-libwbclient-develredhat-upgrade-sambaredhat-upgrade-samba-clientredhat-upgrade-samba-client-libsredhat-upgrade-samba-commonredhat-upgrade-samba-common-libsredhat-upgrade-samba-common-toolsredhat-upgrade-samba-dcredhat-upgrade-samba-dc-libsredhat-upgrade-samba-debuginforedhat-upgrade-samba-develredhat-upgrade-samba-libsredhat-upgrade-samba-pidlredhat-upgrade-samba-pythonredhat-upgrade-samba-testredhat-upgrade-samba-test-develredhat-upgrade-samba-test-libsredhat-upgrade-samba-vfs-glusterfsredhat-upgrade-samba-winbindredhat-upgrade-samba-winbind-clientsredhat-upgrade-samba-winbind-krb5-locatorredhat-upgrade-samba-winbind-modulesredhat-upgrade-samba4redhat-upgrade-samba4-clientredhat-upgrade-samba4-commonredhat-upgrade-samba4-dcredhat-upgrade-samba4-dc-libsredhat-upgrade-samba4-debuginforedhat-upgrade-samba4-develredhat-upgrade-samba4-libsredhat-upgrade-samba4-pidlredhat-upgrade-samba4-pythonredhat-upgrade-samba4-testredhat-upgrade-samba4-winbindredhat-upgrade-samba4-winbind-clientsredhat-upgrade-samba4-winbind-krb5-locator
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.