CVE-2016-2119
published 2016-07-07CVE-2016-2119: libcli/smb/smbXcli_base.c in Samba 4.x before 4.2.14, 4.3.x before 4.3.11, and 4.4.x before 4.4.5 allows man-in-the-middle attackers to bypass a client-signing…
PriorityP341high7.5CVSS 3.1
AVNACHPRNUIRSUCHIHAH
EPSS
3.10%
86.4th percentile
libcli/smb/smbXcli_base.c in Samba 4.x before 4.2.14, 4.3.x before 4.3.11, and 4.4.x before 4.4.5 allows man-in-the-middle attackers to bypass a client-signing protection mechanism, and consequently spoof SMB2 and SMB3 servers, via the (1) SMB2_SESSION_FLAG_IS_GUEST or (2) SMB2_SESSION_FLAG_IS_NULL flag.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | samba | < samba 2:4.4.5+dfsg-1 (bookworm) | samba 2:4.4.5+dfsg-1 (bookworm) |
| samba | samba | >= 0 < 2:4.4.5+dfsg-1 | 2:4.4.5+dfsg-1 |
| samba | samba | >= 0 < 2:4.4.5+dfsg-1 | 2:4.4.5+dfsg-1 |
| samba | samba | >= 0 < 2:4.4.5+dfsg-1 | 2:4.4.5+dfsg-1 |
| samba | samba | >= 0 < 2:4.4.5+dfsg-1 | 2:4.4.5+dfsg-1 |
| samba | samba | >= 4.0.0 < 4.2.14 | 4.2.14 |
| samba | samba | >= 4.3.0 < 4.3.11 | 4.3.11 |
| samba | samba | >= 4.4.0 < 4.4.5 | 4.4.5 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Samba vulnerability
vendor_ubuntu·2016-09-28
CVE-2016-2119 Samba vulnerability
Title: Samba vulnerability
Summary: Samba could be tricked into connecting to impersonated servers.
Stefan Metzmacher discovered that Samba incorrectly handled certain flags
in SMB2/3 client connections. A remote attacker could use this issue to
disable client signing and impersonate servers by performing a
machine-in-the-middle attack.
Samba has been updated to 4.3.11 in Ubuntu 14.04 LTS and Ubuntu 16.04 LTS.
In addition to the security fix, the updated packages contain bug fixes,
new features, and possibly incompatible changes.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the necessary
changes.
Red Hat
samba: Client side SMB2/3 required signing can be downgraded
vendor_redhat·2016-07-07·CVSS 7.5
CVE-2016-2119 [HIGH] samba: Client side SMB2/3 required signing can be downgraded
samba: Client side SMB2/3 required signing can be downgraded
libcli/smb/smbXcli_base.c in Samba 4.x before 4.2.14, 4.3.x before 4.3.11, and 4.4.x before 4.4.5 allows man-in-the-middle attackers to bypass a client-signing protection mechanism, and consequently spoof SMB2 and SMB3 servers, via the (1) SMB2_SESSION_FLAG_IS_GUEST or (2) SMB2_SESSION_FLAG_IS_NULL flag.
A flaw was found in the way Samba initiated signed DCE/RPC connections. A man-in-the-middle attacker could use this flaw to downgrade the connection to not use signing and therefore impersonate the server.
Package: samba (Red Hat Enterprise Linux 5) - Not affected
Package: samba (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2016-2119: samba - libcli/smb/smbXcli_base.c in Samba 4.x before 4.2.14, 4.3.x before 4.3.11, and 4...
vendor_debian·2016·CVSS 7.5
CVE-2016-2119 [HIGH] CVE-2016-2119: samba - libcli/smb/smbXcli_base.c in Samba 4.x before 4.2.14, 4.3.x before 4.3.11, and 4...
libcli/smb/smbXcli_base.c in Samba 4.x before 4.2.14, 4.3.x before 4.3.11, and 4.4.x before 4.4.5 allows man-in-the-middle attackers to bypass a client-signing protection mechanism, and consequently spoof SMB2 and SMB3 servers, via the (1) SMB2_SESSION_FLAG_IS_GUEST or (2) SMB2_SESSION_FLAG_IS_NULL flag.
Scope: local
bookworm: resolved (fixed in 2:4.4.5+dfsg-1)
bullseye: resolved (fixed in 2:4.4.5+dfsg-1)
forky: resolved (fixed in 2:4.4.5+dfsg-1)
sid: resolved (fixed in 2:4.4.5+dfsg-1)
trixie: resolved (fixed in 2:4.4.5+dfsg-1)
GHSA
GHSA-6hfw-45v2-4p3j: libcli/smb/smbXcli_base
ghsa_unreviewed·2022-05-14
CVE-2016-2119 [HIGH] CWE-284 GHSA-6hfw-45v2-4p3j: libcli/smb/smbXcli_base
libcli/smb/smbXcli_base.c in Samba 4.x before 4.2.14, 4.3.x before 4.3.11, and 4.4.x before 4.4.5 allows man-in-the-middle attackers to bypass a client-signing protection mechanism, and consequently spoof SMB2 and SMB3 servers, via the (1) SMB2_SESSION_FLAG_IS_GUEST or (2) SMB2_SESSION_FLAG_IS_NULL flag.
OSV
CVE-2016-2119: libcli/smb/smbXcli_base
osv·2016-07-07·CVSS 7.5
CVE-2016-2119 [HIGH] CVE-2016-2119: libcli/smb/smbXcli_base
libcli/smb/smbXcli_base.c in Samba 4.x before 4.2.14, 4.3.x before 4.3.11, and 4.4.x before 4.4.5 allows man-in-the-middle attackers to bypass a client-signing protection mechanism, and consequently spoof SMB2 and SMB3 servers, via the (1) SMB2_SESSION_FLAG_IS_GUEST or (2) SMB2_SESSION_FLAG_IS_NULL flag.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-7855 flash-plugin: use-after-free issue fixed in APSB16-36
bugzilla·2016-10-26·CVSS 8.8
CVE-2016-7855 [HIGH] CVE-2016-7855 flash-plugin: use-after-free issue fixed in APSB16-36
CVE-2016-7855 flash-plugin: use-after-free issue fixed in APSB16-36
Adobe Security Bulletin APSB16-36 for Adobe Flash Player describes a flaw that can possibly lead to code execution when Flash Player is used to play a specially crafted SWF file.
Quoting from the APSB16-36:
These updates resolve a use-after-free vulnerability that could lead to code
execution (CVE-2016-7855).
External References:
https://helpx.adobe.com/security/products/flash-player/apsb16-36.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 5 Supplementary
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2016:2119 https://rhn.redhat.com/errata/RHSA-2016-2119.html
Bugzilla
CVE-2016-2119 samba: Client side SMB2/3 required signing can be downgraded [fedora-all]
bugzilla·2016-07-07·CVSS 7.5
CVE-2016-2119 [HIGH] CVE-2016-2119 samba: Client side SMB2/3 required signing can be downgraded [fedora-all]
CVE-2016-2119 samba: Client side SMB2/3 required signing can be downgraded [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported ve
Bugzilla
CVE-2016-2119 samba: Client side SMB2/3 required signing can be downgraded
bugzilla·2016-07-01·CVSS 7.5
CVE-2016-2119 [HIGH] CVE-2016-2119 samba: Client side SMB2/3 required signing can be downgraded
CVE-2016-2119 samba: Client side SMB2/3 required signing can be downgraded
As per upstream advisory:
It's possible for an attacker to downgrade the required signing for an SMB2/3 client connection, by injecting the SMB2_SESSION_FLAG_IS_GUEST or SMB2_SESSION_FLAG_IS_NULL flags.
This applies to the combination of "client ipc signing" and "client ipc max protocol" in their effective default settings ("mandatory" and "SMB3_11").
The combination of "client signing" and "client max protocol" is also affected, but only if "client signing" is explicitly set (as the effective default is "if_required") and "client max protocol" is explicitly set to SMB2 or higher.
Discussion:
Acknowledgments:
Name: the Samba project
Upstream: Stefan Metzmacher
---
Public via:
https://www.samba.org/samba/s
http://lists.opensuse.org/opensuse-updates/2016-07/msg00060.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1486.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1487.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1494.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.htmlhttp://www.securityfocus.com/bid/91700http://www.securitytracker.com/id/1036244https://security.gentoo.org/glsa/201805-07https://www.samba.org/samba/security/CVE-2016-2119.htmlhttp://lists.opensuse.org/opensuse-updates/2016-07/msg00060.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1486.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1487.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1494.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.htmlhttp://www.securityfocus.com/bid/91700http://www.securitytracker.com/id/1036244https://security.gentoo.org/glsa/201805-07https://www.samba.org/samba/security/CVE-2016-2119.html
2016-07-07
Published