cbcvebase.
CVE-2017-12151
published 2018-07-27

CVE-2017-12151: A flaw was found in the way samba client before samba 4.4.16, samba 4.5.14 and samba 4.6.8 used encryption with the max protocol set as SMB3. The connection…

high7.4CVSS 3.0
AVNACHPRNUINSUCHIHAN
A flaw was found in the way samba client before samba 4.4.16, samba 4.5.14 and samba 4.6.8 used encryption with the max protocol set as SMB3. The connection could lose the requirement for signing and encrypting to any DFS redirects, allowing an attacker to read or alter the contents of the connection via a man-in-the-middle attack.

Affected

22 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debiansamba< samba 2:4.6.7+dfsg-2 (bookworm)samba 2:4.6.7+dfsg-2 (bookworm)
debiansamba
hpcifs_server
red_hat_incgluster_storage_for_rhel_6
redhatenterprise_linux
redhatenterprise_linux_desktop
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_eus
redhatenterprise_linux_workstation
redhatgluster_storage
sambasamba< 4.4.164.4.16
sambasamba>= 0 < 2:4.6.7+dfsg-22:4.6.7+dfsg-2
sambasamba>= 0 < 2:4.6.7+dfsg-22:4.6.7+dfsg-2
sambasamba>= 0 < 2:4.6.7+dfsg-22:4.6.7+dfsg-2
sambasamba>= 0 < 2:4.6.7+dfsg-22:4.6.7+dfsg-2
sambasamba>= 0 < 2:4.3.11+dfsg-0ubuntu0.14.04.122:4.3.11+dfsg-0ubuntu0.14.04.12
sambasamba>= 0 < 2:4.3.11+dfsg-0ubuntu0.16.04.112:4.3.11+dfsg-0ubuntu0.16.04.11
sambasamba>= 4.5.0 < 4.5.144.5.14
sambasamba>= 4.6.0 < 4.6.84.6.8

CVSS provenance

nvdv3.07.4HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
osv7.4HIGH