CVE-2015-5296
published 2015-12-29CVE-2015-5296: Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 supports connections that are encrypted but unsigned, which allows…
PriorityP433medium5.4CVSS 3.1
AVNACHPRNUINSCCLILAN
EPSS
7.26%
93.7th percentile
Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 supports connections that are encrypted but unsigned, which allows man-in-the-middle attackers to conduct encrypted-to-unencrypted downgrade attacks by modifying the client-server data stream, related to clidfs.c, libsmb_server.c, and smbXcli_base.c.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | samba | < samba 2:4.1.22+dfsg-1 (bookworm) | samba 2:4.1.22+dfsg-1 (bookworm) |
| samba | samba | >= 0 < 2:4.1.22+dfsg-1 | 2:4.1.22+dfsg-1 |
| samba | samba | >= 0 < 2:4.1.22+dfsg-1 | 2:4.1.22+dfsg-1 |
| samba | samba | >= 0 < 2:4.1.22+dfsg-1 | 2:4.1.22+dfsg-1 |
| samba | samba | >= 0 < 2:4.1.22+dfsg-1 | 2:4.1.22+dfsg-1 |
| samba | samba | >= 0 < 2:4.1.6+dfsg-1ubuntu2.14.04.11 | 2:4.1.6+dfsg-1ubuntu2.14.04.11 |
| samba | samba | >= 0 < 2:4.1.6+dfsg-1ubuntu2.14.04.12 | 2:4.1.6+dfsg-1ubuntu2.14.04.12 |
| samba | samba | >= 3.2.0 < 4.1.22 | 4.1.22 |
| samba | samba | >= 4.2.0 < 4.2.7 | 4.2.7 |
| samba | samba | >= 4.3.0 < 4.3.3 | 4.3.3 |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv5.4MEDIUM
vendor_debian5.4MEDIUM
vendor_redhat5.4MEDIUM
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pcgp-3vvv-qw57: Samba 3
ghsa_unreviewed·2022-05-14
CVE-2015-5296 [MEDIUM] CWE-20 GHSA-pcgp-3vvv-qw57: Samba 3
Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 supports connections that are encrypted but unsigned, which allows man-in-the-middle attackers to conduct encrypted-to-unencrypted downgrade attacks by modifying the client-server data stream, related to clidfs.c, libsmb_server.c, and smbXcli_base.c.
OSV
samba regression
osv·2016-02-16·CVSS 5.3
CVE-2015-5252 [MEDIUM] samba regression
samba regression
USN-2855-1 fixed vulnerabilities in Samba. The upstream fix for
CVE-2015-5252 introduced a regression in certain specific environments.
This update fixes the problem.
Original advisory details:
Thilo Uttendorfer discovered that the Samba LDAP server incorrectly handled
certain packets. A remote attacker could use this issue to cause the LDAP
server to stop responding, resulting in a denial of service. This issue
only affected Ubuntu 14.04 LTS, Ubuntu 15.04 and Ubuntu 15.10.
(CVE-2015-3223)
Jan Kasprzak discovered that Samba incorrectly handled certain symlinks. A
remote attacker could use this issue to access files outside the exported
share path. (CVE-2015-5252)
Stefan Metzmacher discovered that Samba did not enforce signing when
creating encrypted connections. If a
OSV
samba vulnerabilities
osv·2016-01-05·CVSS 5.3
CVE-2015-3223 [MEDIUM] samba vulnerabilities
samba vulnerabilities
Thilo Uttendorfer discovered that the Samba LDAP server incorrectly handled
certain packets. A remote attacker could use this issue to cause the LDAP
server to stop responding, resulting in a denial of service. This issue
only affected Ubuntu 14.04 LTS, Ubuntu 15.04 and Ubuntu 15.10.
(CVE-2015-3223)
Jan Kasprzak discovered that Samba incorrectly handled certain symlinks. A
remote attacker could use this issue to access files outside the exported
share path. (CVE-2015-5252)
Stefan Metzmacher discovered that Samba did not enforce signing when
creating encrypted connections. If a remote attacker were able to perform a
machine-in-the-middle attack, this flaw could be exploited to view sensitive
information. (CVE-2015-5296)
It was discovered that Samba incorrectly perf
OSV
CVE-2015-5296: Samba 3
osv·2015-12-29·CVSS 5.4
CVE-2015-5296 [MEDIUM] CVE-2015-5296: Samba 3
Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 supports connections that are encrypted but unsigned, which allows man-in-the-middle attackers to conduct encrypted-to-unencrypted downgrade attacks by modifying the client-server data stream, related to clidfs.c, libsmb_server.c, and smbXcli_base.c.
Ubuntu
Samba regression
vendor_ubuntu·2016-02-16·CVSS 5.3
CVE-2015-5252 [MEDIUM] Samba regression
Title: Samba regression
Summary: USN-2855-1 introduced a regression in Samba.
USN-2855-1 fixed vulnerabilities in Samba. The upstream fix for
CVE-2015-5252 introduced a regression in certain specific environments.
This update fixes the problem.
Original advisory details:
Thilo Uttendorfer discovered that the Samba LDAP server incorrectly handled
certain packets. A remote attacker could use this issue to cause the LDAP
server to stop responding, resulting in a denial of service. This issue
only affected Ubuntu 14.04 LTS, Ubuntu 15.04 and Ubuntu 15.10.
(CVE-2015-3223)
Jan Kasprzak discovered that Samba incorrectly handled certain symlinks. A
remote attacker could use this issue to access files outside the exported
share path. (CVE-2015-5252)
Stefan Metzmacher discovered that Samba did
Ubuntu
Samba vulnerabilities
vendor_ubuntu·2016-01-05·CVSS 5.3
CVE-2015-3223 [MEDIUM] Samba vulnerabilities
Title: Samba vulnerabilities
Summary: Several security issues were fixed in Samba.
Thilo Uttendorfer discovered that the Samba LDAP server incorrectly handled
certain packets. A remote attacker could use this issue to cause the LDAP
server to stop responding, resulting in a denial of service. This issue
only affected Ubuntu 14.04 LTS, Ubuntu 15.04 and Ubuntu 15.10.
(CVE-2015-3223)
Jan Kasprzak discovered that Samba incorrectly handled certain symlinks. A
remote attacker could use this issue to access files outside the exported
share path. (CVE-2015-5252)
Stefan Metzmacher discovered that Samba did not enforce signing when
creating encrypted connections. If a remote attacker were able to perform a
machine-in-the-middle attack, this flaw could be exploited to view sensitive
information.
Red Hat
samba: client requesting encryption vulnerable to downgrade attack
vendor_redhat·2015-12-16·CVSS 5.4
CVE-2015-5296 [MEDIUM] CWE-345 samba: client requesting encryption vulnerable to downgrade attack
samba: client requesting encryption vulnerable to downgrade attack
Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 supports connections that are encrypted but unsigned, which allows man-in-the-middle attackers to conduct encrypted-to-unencrypted downgrade attacks by modifying the client-server data stream, related to clidfs.c, libsmb_server.c, and smbXcli_base.c.
A man-in-the-middle vulnerability was found in the way "connection signing" was implemented by Samba. A remote attacker could use this flaw to downgrade an existing Samba client connection and force the use of plain text.
Package: samba (Red Hat Enterprise Linux 5) - Not affected
Package: samba3x (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2015-5296: samba - Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 supp...
vendor_debian·2015·CVSS 5.4
CVE-2015-5296 [MEDIUM] CVE-2015-5296: samba - Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 supp...
Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 supports connections that are encrypted but unsigned, which allows man-in-the-middle attackers to conduct encrypted-to-unencrypted downgrade attacks by modifying the client-server data stream, related to clidfs.c, libsmb_server.c, and smbXcli_base.c.
Scope: local
bookworm: resolved (fixed in 2:4.1.22+dfsg-1)
bullseye: resolved (fixed in 2:4.1.22+dfsg-1)
forky: resolved (fixed in 2:4.1.22+dfsg-1)
sid: resolved (fixed in 2:4.1.22+dfsg-1)
trixie: resolved (fixed in 2:4.1.22+dfsg-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-12150 samba: Some code path don't enforce smb signing, when they should
bugzilla·2017-09-05·CVSS 5.4
CVE-2017-12150 [MEDIUM] CVE-2017-12150 samba: Some code path don't enforce smb signing, when they should
CVE-2017-12150 samba: Some code path don't enforce smb signing, when they should
There are several code paths where the code doesn't enforce SMB signing:
* The fixes for CVE-2015-5296 didn't apply the implied signing protection
when enforcing encryption for commands like 'smb2mount -e', 'smbcacls -e' and
'smbcquotas -e'.
* The python binding exported as 'samba.samba3.libsmb_samba_internal'
doesn't make use of the "client signing" smb.conf option.
* libgpo as well as 'net ads gpo' doesn't require SMB signing when fetching
group policies.
* Commandline tools like 'smbclient', 'smbcacls' and 'smbcquotas' allow
a fallback to an anonymous connection when using the '--use-ccache'
option and this happens even if SMB signing is required.
Discussion:
Acknowledgments:
Name: the Samba project
Bugzilla
CVE-2015-5299 CVE-2015-7540 CVE-2015-3223 CVE-2015-5252 CVE-2015-5296 samba: various flaws [fedora-all]
bugzilla·2015-12-16·CVSS 5.3
CVE-2015-5299 [MEDIUM] CVE-2015-5299 CVE-2015-7540 CVE-2015-3223 CVE-2015-5252 CVE-2015-5296 samba: various flaws [fedora-all]
CVE-2015-5299 CVE-2015-7540 CVE-2015-3223 CVE-2015-5252 CVE-2015-5296 samba: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multi
Bugzilla
CVE-2015-5296 samba: client requesting encryption vulnerable to downgrade attack
bugzilla·2015-12-10·CVSS 5.4
CVE-2015-5296 [MEDIUM] CVE-2015-5296 samba: client requesting encryption vulnerable to downgrade attack
CVE-2015-5296 samba: client requesting encryption vulnerable to downgrade attack
As per upstream samba advisory:
Versions of Samba from 3.2.0 to 4.3.2 inclusive do not ensure that signing is negotiated when creating an encrypted client connection to
a server.
Without this a man-in-the-middle attack could downgrade the connection and connect using the supplied credentials as an unsigned, unencrypted
connection.
The following mitigation was suggested by upstream:
When using the smbclient command, always add the argument "--signing=required" when using the "-e" or "--encrypt" argument.
Alternatively, set the variable "client signing = mandatory" in the [global] section of the smb.conf file on any client using encrypted connections.
To protect a Samba server exporting encrypted shares
http://lists.fedoraproject.org/pipermail/package-announce/2015-December/174076.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-December/174391.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00019.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00032.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00033.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00042.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00047.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00048.htmlhttp://www.debian.org/security/2016/dsa-3433http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.securityfocus.com/bid/79732http://www.securitytracker.com/id/1034493http://www.ubuntu.com/usn/USN-2855-1http://www.ubuntu.com/usn/USN-2855-2https://bugzilla.redhat.com/show_bug.cgi?id=1290292https://git.samba.org/?p=samba.git%3Ba=commit%3Bh=1ba49b8f389eda3414b14410c7fbcb4041ca06b1https://git.samba.org/?p=samba.git%3Ba=commit%3Bh=a819d2b440aafa3138d95ff6e8b824da885a70e9https://git.samba.org/?p=samba.git%3Ba=commit%3Bh=d724f835acb9f4886c0001af32cd325dbbf1f895https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05115993https://security.gentoo.org/glsa/201612-47https://www.samba.org/samba/security/CVE-2015-5296.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-December/174076.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-December/174391.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00019.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00032.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00033.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00042.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00047.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00048.htmlhttp://www.debian.org/security/2016/dsa-3433http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.securityfocus.com/bid/79732http://www.securitytracker.com/id/1034493http://www.ubuntu.com/usn/USN-2855-1http://www.ubuntu.com/usn/USN-2855-2https://bugzilla.redhat.com/show_bug.cgi?id=1290292https://git.samba.org/?p=samba.git%3Ba=commit%3Bh=1ba49b8f389eda3414b14410c7fbcb4041ca06b1https://git.samba.org/?p=samba.git%3Ba=commit%3Bh=a819d2b440aafa3138d95ff6e8b824da885a70e9https://git.samba.org/?p=samba.git%3Ba=commit%3Bh=d724f835acb9f4886c0001af32cd325dbbf1f895https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05115993https://security.gentoo.org/glsa/201612-47https://www.samba.org/samba/security/CVE-2015-5296.html
2015-12-29
Published