CVE-2016-2114
25.04.2016, 00:59
The SMB1 protocol implementation in Samba 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not recognize the "server signing = mandatory" setting, which allows man-in-the-middle attackers to spoof SMB servers by modifying the client-server data stream.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| samba | samba | 4.0.0 |
| samba | samba | 4.0.1 |
| samba | samba | 4.0.2 |
| samba | samba | 4.0.3 |
| samba | samba | 4.0.4 |
| samba | samba | 4.0.5 |
| samba | samba | 4.0.6 |
| samba | samba | 4.0.7 |
| samba | samba | 4.0.8 |
| samba | samba | 4.0.9 |
| samba | samba | 4.0.10 |
| samba | samba | 4.0.11 |
| samba | samba | 4.0.12 |
| samba | samba | 4.0.13 |
| samba | samba | 4.0.14 |
| samba | samba | 4.0.15 |
| samba | samba | 4.0.16 |
| samba | samba | 4.0.17 |
| samba | samba | 4.0.18 |
| samba | samba | 4.0.19 |
| samba | samba | 4.0.20 |
| samba | samba | 4.0.21 |
| samba | samba | 4.0.22 |
| samba | samba | 4.0.23 |
| samba | samba | 4.0.24 |
| samba | samba | 4.0.25 |
| samba | samba | 4.0.26 |
| samba | samba | 4.1.0 |
| samba | samba | 4.1.1 |
| samba | samba | 4.1.2 |
| samba | samba | 4.1.3 |
| samba | samba | 4.1.4 |
| samba | samba | 4.1.5 |
| samba | samba | 4.1.6 |
| samba | samba | 4.1.7 |
| samba | samba | 4.1.8 |
| samba | samba | 4.1.9 |
| samba | samba | 4.1.10 |
| samba | samba | 4.1.11 |
| samba | samba | 4.1.12 |
| samba | samba | 4.1.13 |
| samba | samba | 4.1.14 |
| samba | samba | 4.1.15 |
| samba | samba | 4.1.16 |
| samba | samba | 4.1.17 |
| samba | samba | 4.1.18 |
| samba | samba | 4.1.19 |
| samba | samba | 4.1.20 |
| samba | samba | 4.1.21 |
| samba | samba | 4.1.22 |
| samba | samba | 4.1.23 |
| samba | samba | 4.2.0:rc1 |
| samba | samba | 4.2.0:rc2 |
| samba | samba | 4.2.0:rc3 |
| samba | samba | 4.2.0:rc4 |
| samba | samba | 4.2.1 |
| samba | samba | 4.2.2 |
| samba | samba | 4.2.3 |
| samba | samba | 4.2.4 |
| samba | samba | 4.2.5 |
| samba | samba | 4.2.6 |
| samba | samba | 4.2.7 |
| samba | samba | 4.2.8 |
| samba | samba | 4.2.9 |
| samba | samba | 4.3.0 |
| samba | samba | 4.3.1 |
| samba | samba | 4.3.2 |
| samba | samba | 4.3.3 |
| samba | samba | 4.3.4 |
| samba | samba | 4.3.5 |
| samba | samba | 4.3.6 |
| samba | samba | 4.4.0 |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 15.10 |
| canonical | ubuntu_linux | 16.04 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| samba |
| ||||||||||||
| samba4 |
|
Red Hat Enterprise Linux Releases
Red Hat Product | |||||
|---|---|---|---|---|---|
| ctdb |
| ||||
| ctdb-devel |
| ||||
| ctdb-tests |
| ||||
| ipa-admintools |
| ||||
| ipa-client |
| ||||
| ipa-python |
| ||||
| ipa-server |
| ||||
| ipa-server-dns |
| ||||
| ipa-server-selinux |
| ||||
| ipa-server-trust-ad |
| ||||
| ldb-tools |
| ||||
| libldb |
| ||||
| libldb-devel |
| ||||
| libsmbclient |
| ||||
| libsmbclient-devel |
| ||||
| libtalloc |
| ||||
| libtalloc-devel |
| ||||
| libtdb |
| ||||
| libtdb-devel |
| ||||
| libtevent |
| ||||
| libtevent-devel |
| ||||
| libwbclient |
| ||||
| libwbclient-devel |
| ||||
| openchange |
| ||||
| openchange-client |
| ||||
| openchange-devel |
| ||||
| openchange-devel-docs |
| ||||
| pyldb |
| ||||
| pyldb-devel |
| ||||
| pytalloc |
| ||||
| pytalloc-devel |
| ||||
| python-tdb |
| ||||
| python-tevent |
| ||||
| samba |
| ||||
| samba-client |
| ||||
| samba-client-libs |
| ||||
| samba-common |
| ||||
| samba-common-libs |
| ||||
| samba-common-tools |
| ||||
| samba-dc |
| ||||
| samba-dc-libs |
| ||||
| samba-devel |
| ||||
| samba-libs |
| ||||
| samba-pidl |
| ||||
| samba-python |
| ||||
| samba-test |
| ||||
| samba-test-devel |
| ||||
| samba-test-libs |
| ||||
| samba-vfs-glusterfs |
| ||||
| samba-winbind |
| ||||
| samba-winbind-clients |
| ||||
| samba-winbind-krb5-locator |
| ||||
| samba-winbind-modules |
| ||||
| samba4 |
| ||||
| samba4-client |
| ||||
| samba4-common |
| ||||
| samba4-dc |
| ||||
| samba4-dc-libs |
| ||||
| samba4-devel |
| ||||
| samba4-libs |
| ||||
| samba4-pidl |
| ||||
| samba4-python |
| ||||
| samba4-test |
| ||||
| samba4-winbind |
| ||||
| samba4-winbind-clients |
| ||||
| samba4-winbind-krb5-locator |
| ||||
| tdb-tools |
|
Common Weakness Enumeration