CVE-2016-2125
published 2018-10-31CVE-2016-2125: It was found that Samba before versions 4.5.3, 4.4.8, 4.3.13 always requested forwardable tickets when using Kerberos authentication. A service to which Samba…
PriorityP338medium6.5CVSS 3.1
AVAACLPRNUINSUCHINAN
EPSS
9.20%
94.8th percentile
It was found that Samba before versions 4.5.3, 4.4.8, 4.3.13 always requested forwardable tickets when using Kerberos authentication. A service to which Samba authenticated using Kerberos could subsequently use the ticket to impersonate Samba to other services or domain users.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | samba | < samba 2:4.5.2+dfsg-2 (bookworm) | samba 2:4.5.2+dfsg-2 (bookworm) |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | gluster_storage | — | — |
| samba | samba | >= 0 < 2:4.5.2+dfsg-2 | 2:4.5.2+dfsg-2 |
| samba | samba | >= 0 < 2:4.5.2+dfsg-2 | 2:4.5.2+dfsg-2 |
| samba | samba | >= 0 < 2:4.5.2+dfsg-2 | 2:4.5.2+dfsg-2 |
| samba | samba | >= 0 < 2:4.5.2+dfsg-2 | 2:4.5.2+dfsg-2 |
| samba | samba | >= 0 < 2:4.3.11+dfsg-0ubuntu0.14.04.4 | 2:4.3.11+dfsg-0ubuntu0.14.04.4 |
| samba | samba | >= 0 < 2:4.3.11+dfsg-0ubuntu0.16.04.3 | 2:4.3.11+dfsg-0ubuntu0.16.04.3 |
| samba | samba | >= 3.0.25 < 4.3.13 | 4.3.13 |
| samba | samba | >= 4.4.0 < 4.4.8 | 4.4.8 |
| samba | samba | >= 4.5.0 < 4.5.3 | 4.5.3 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv3.06.4MEDIUMCVSS:3.0/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
nvdv2.03.3LOWAV:A/AC:L/Au:N/C:P/I:N/A:N
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
samba: Unconditional privilege delegation to Kerberos servers in trusted realms
vendor_redhat·2016-12-19·CVSS 6.5
CVE-2016-2125 [MEDIUM] CWE-287 samba: Unconditional privilege delegation to Kerberos servers in trusted realms
samba: Unconditional privilege delegation to Kerberos servers in trusted realms
It was found that Samba before versions 4.5.3, 4.4.8, 4.3.13 always requested forwardable tickets when using Kerberos authentication. A service to which Samba authenticated using Kerberos could subsequently use the ticket to impersonate Samba to other services or domain users.
It was found that Samba always requested forwardable tickets when using Kerberos authentication. A service to which Samba authenticated using Kerberos could subsequently use the ticket to impersonate Samba to other services or domain users.
Mitigation: The following mitigation is suggested by upstream.
The samba-tool command and the AD DC mode honours the undocumented "gensec_gssapi:delegation=no" option in the [global] section of the
Ubuntu
Samba vulnerabilities
vendor_ubuntu·2016-12-19·CVSS 8.8
CVE-2016-2123 [HIGH] Samba vulnerabilities
Title: Samba vulnerabilities
Summary: Several security issues were fixed in Samba.
Frederic Besler and others discovered that the ndr_pull_dnsp_nam
function in Samba contained an integer overflow. An authenticated
attacker could use this to gain administrative privileges. This issue
only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 16.10.
(CVE-2016-2123)
Simo Sorce discovered that that Samba clients always requested
a forwardable ticket when using Kerberos authentication. An
attacker could use this to impersonate an authenticated user or
service. (CVE-2016-2125)
Volker Lendecke discovered that Kerberos PAC validation implementation
in Samba contained multiple vulnerabilities. An authenticated attacker
could use this to cause a denial of service or gain administrative
privile
Debian
CVE-2016-2125: samba - It was found that Samba before versions 4.5.3, 4.4.8, 4.3.13 always requested fo...
vendor_debian·2016·CVSS 6.5
CVE-2016-2125 [MEDIUM] CVE-2016-2125: samba - It was found that Samba before versions 4.5.3, 4.4.8, 4.3.13 always requested fo...
It was found that Samba before versions 4.5.3, 4.4.8, 4.3.13 always requested forwardable tickets when using Kerberos authentication. A service to which Samba authenticated using Kerberos could subsequently use the ticket to impersonate Samba to other services or domain users.
Scope: local
bookworm: resolved (fixed in 2:4.5.2+dfsg-2)
bullseye: resolved (fixed in 2:4.5.2+dfsg-2)
forky: resolved (fixed in 2:4.5.2+dfsg-2)
sid: resolved (fixed in 2:4.5.2+dfsg-2)
trixie: resolved (fixed in 2:4.5.2+dfsg-2)
GHSA
GHSA-qc7g-mqp8-fhmm: It was found that Samba before versions 4
ghsa_unreviewed·2022-05-13
CVE-2016-2125 [MEDIUM] CWE-20 GHSA-qc7g-mqp8-fhmm: It was found that Samba before versions 4
It was found that Samba before versions 4.5.3, 4.4.8, 4.3.13 always requested forwardable tickets when using Kerberos authentication. A service to which Samba authenticated using Kerberos could subsequently use the ticket to impersonate Samba to other services or domain users.
OSV
CVE-2016-2125: It was found that Samba before versions 4
osv·2018-10-31·CVSS 6.5
CVE-2016-2125 [MEDIUM] CVE-2016-2125: It was found that Samba before versions 4
It was found that Samba before versions 4.5.3, 4.4.8, 4.3.13 always requested forwardable tickets when using Kerberos authentication. A service to which Samba authenticated using Kerberos could subsequently use the ticket to impersonate Samba to other services or domain users.
OSV
samba vulnerabilities
osv·2016-12-19·CVSS 8.8
CVE-2016-2123 [HIGH] samba vulnerabilities
samba vulnerabilities
Frederic Besler and others discovered that the ndr_pull_dnsp_nam
function in Samba contained an integer overflow. An authenticated
attacker could use this to gain administrative privileges. This issue
only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 16.10.
(CVE-2016-2123)
Simo Sorce discovered that that Samba clients always requested
a forwardable ticket when using Kerberos authentication. An
attacker could use this to impersonate an authenticated user or
service. (CVE-2016-2125)
Volker Lendecke discovered that Kerberos PAC validation implementation
in Samba contained multiple vulnerabilities. An authenticated attacker
could use this to cause a denial of service or gain administrative
privileges. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04
L
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-2125 CVE-2016-2126 samba: various flaws [fedora-all]
bugzilla·2016-12-19·CVSS 6.5
CVE-2016-2125 [MEDIUM] CVE-2016-2125 CVE-2016-2126 samba: various flaws [fedora-all]
CVE-2016-2125 CVE-2016-2126 samba: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While on
Bugzilla
CVE-2016-2125 samba: Unconditional privilege delegation to Kerberos servers in trusted realms
bugzilla·2016-12-09·CVSS 6.5
CVE-2016-2125 [MEDIUM] CVE-2016-2125 samba: Unconditional privilege delegation to Kerberos servers in trusted realms
CVE-2016-2125 samba: Unconditional privilege delegation to Kerberos servers in trusted realms
As per upstream:
Samba client code always requests a forwardable ticket when using Kerberos authentication. This means the target server, which must be in the current or trusted domain/realm, is given a valid general purpose Kerberos "Ticket Granting Ticket" (TGT), which can be used to fully impersonate the authenticated user or service.
The risks of impersonation of the client are similar to the well known risks from forwarding of NTLM credentials, with two important differences:
- NTLM forwarding can and should be mitigated with packet signing
- Kerberos forwarding can only be attempted after the trusted destination server decrypts the ticket.
Finally, it should be noted that typically the c
http://rhn.redhat.com/errata/RHSA-2017-0494.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0495.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0662.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0744.htmlhttp://www.securityfocus.com/bid/94988http://www.securitytracker.com/id/1037494https://access.redhat.com/errata/RHSA-2017:1265https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-2125https://www.samba.org/samba/security/CVE-2016-2125.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0494.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0495.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0662.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0744.htmlhttp://www.securityfocus.com/bid/94988http://www.securitytracker.com/id/1037494https://access.redhat.com/errata/RHSA-2017:1265https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-2125https://www.samba.org/samba/security/CVE-2016-2125.html
2018-10-31
Published