CVE-2017-12151
published 2018-07-27CVE-2017-12151: A flaw was found in the way samba client before samba 4.4.16, samba 4.5.14 and samba 4.6.8 used encryption with the max protocol set as SMB3. The connection…
PriorityP343high7.4CVSS 3.0
AVNACHPRNUINSUCHIHAN
EPSS
4.59%
90.6th percentile
A flaw was found in the way samba client before samba 4.4.16, samba 4.5.14 and samba 4.6.8 used encryption with the max protocol set as SMB3. The connection could lose the requirement for signing and encrypting to any DFS redirects, allowing an attacker to read or alter the contents of the connection via a man-in-the-middle attack.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | samba | < samba 2:4.6.7+dfsg-2 (bookworm) | samba 2:4.6.7+dfsg-2 (bookworm) |
| debian | samba | — | — |
| hp | cifs_server | — | — |
| red_hat_inc | gluster_storage_for_rhel_6 | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | gluster_storage | — | — |
| samba | samba | < 4.4.16 | 4.4.16 |
| samba | samba | >= 0 < 2:4.6.7+dfsg-2 | 2:4.6.7+dfsg-2 |
| samba | samba | >= 0 < 2:4.6.7+dfsg-2 | 2:4.6.7+dfsg-2 |
| samba | samba | >= 0 < 2:4.6.7+dfsg-2 | 2:4.6.7+dfsg-2 |
| samba | samba | >= 0 < 2:4.6.7+dfsg-2 | 2:4.6.7+dfsg-2 |
| samba | samba | >= 0 < 2:4.3.11+dfsg-0ubuntu0.14.04.12 | 2:4.3.11+dfsg-0ubuntu0.14.04.12 |
| samba | samba | >= 0 < 2:4.3.11+dfsg-0ubuntu0.16.04.11 | 2:4.3.11+dfsg-0ubuntu0.16.04.11 |
| samba | samba | >= 4.5.0 < 4.5.14 | 4.5.14 |
| samba | samba | >= 4.6.0 < 4.6.8 | 4.6.8 |
CVSS provenance
nvdv3.07.4HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv7.4HIGH
vendor_debian7.4LOW
vendor_redhat7.4HIGH
vendor_ubuntu7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fr73-3m84-8rch: It was discovered that the fix for CVE-2017-12151 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3
ghsa_unreviewed·2022-05-13·CVSS 7.4
CVE-2017-15086 [HIGH] CWE-300 GHSA-fr73-3m84-8rch: It was discovered that the fix for CVE-2017-12151 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3
It was discovered that the fix for CVE-2017-12151 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHEL 6.
GHSA
GHSA-xc7p-hf9j-w53w: A flaw was found in the way samba client before samba 4
ghsa_unreviewed·2022-05-13
CVE-2017-12151 [HIGH] GHSA-xc7p-hf9j-w53w: A flaw was found in the way samba client before samba 4
A flaw was found in the way samba client before samba 4.4.16, samba 4.5.14 and samba 4.6.8 used encryption with the max protocol set as SMB3. The connection could lose the requirement for signing and encrypting to any DFS redirects, allowing an attacker to read or alter the contents of the connection via a man-in-the-middle attack.
OSV
CVE-2017-12151: A flaw was found in the way samba client before samba 4
osv·2018-07-27·CVSS 7.4
CVE-2017-12151 [HIGH] CVE-2017-12151: A flaw was found in the way samba client before samba 4
A flaw was found in the way samba client before samba 4.4.16, samba 4.5.14 and samba 4.6.8 used encryption with the max protocol set as SMB3. The connection could lose the requirement for signing and encrypting to any DFS redirects, allowing an attacker to read or alter the contents of the connection via a man-in-the-middle attack.
OSV
samba vulnerabilities
osv·2017-09-21·CVSS 7.4
CVE-2017-12150 [HIGH] samba vulnerabilities
samba vulnerabilities
Stefan Metzmacher discovered that Samba incorrectly enforced SMB signing in
certain situations. A remote attacker could use this issue to perform a
machine-in-the-middle attack. (CVE-2017-12150)
Stefan Metzmacher discovered that Samba incorrectly handled encryption
across DFS redirects. A remote attacker could use this issue to perform a
machine-in-the-middle attack. (CVE-2017-12151)
Yihan Lian and Zhibin Hu discovered that Samba incorrectly handled memory
when SMB1 is being used. A remote attacker could possibly use this issue to
obtain server memory contents. (CVE-2017-12163)
Red Hat
samba: SMB2 connections don't keep encryption across DFS redirects (incomplete fix of CVE-2017-12151)
vendor_redhat·2017-10-24·CVSS 7.4
CVE-2017-15086 [HIGH] CWE-300 samba: SMB2 connections don't keep encryption across DFS redirects (incomplete fix of CVE-2017-12151)
samba: SMB2 connections don't keep encryption across DFS redirects (incomplete fix of CVE-2017-12151)
It was discovered that the fix for CVE-2017-12151 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHEL 6.
It was discovered that the fix for CVE-2017-12151 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHEL 6.
Package: samba (Red Hat Enterprise Linux 5) - Not affected
Package: samba3x (Red Hat Enterprise Linux 5) - Not affected
Package: samba (Red Hat Enterprise Linux 6) - Not affected
Package: samba4 (Red Hat Enterprise Linux 6) - Not affected
Package: samba (Red Hat Enterprise Linux 7) - Not affected
Ubuntu
Samba vulnerabilities
vendor_ubuntu·2017-09-21·CVSS 7.4
CVE-2017-12150 [HIGH] Samba vulnerabilities
Title: Samba vulnerabilities
Summary: Samba could be made to expose sensitive information over the network.
Stefan Metzmacher discovered that Samba incorrectly enforced SMB signing in
certain situations. A remote attacker could use this issue to perform a
machine-in-the-middle attack. (CVE-2017-12150)
Stefan Metzmacher discovered that Samba incorrectly handled encryption
across DFS redirects. A remote attacker could use this issue to perform a
machine-in-the-middle attack. (CVE-2017-12151)
Yihan Lian and Zhibin Hu discovered that Samba incorrectly handled memory
when SMB1 is being used. A remote attacker could possibly use this issue to
obtain server memory contents. (CVE-2017-12163)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
samba: SMB2 connections don't keep encryption across DFS redirects
vendor_redhat·2017-09-20·CVSS 7.4
CVE-2017-12151 [HIGH] CWE-300 samba: SMB2 connections don't keep encryption across DFS redirects
samba: SMB2 connections don't keep encryption across DFS redirects
A flaw was found in the way samba client before samba 4.4.16, samba 4.5.14 and samba 4.6.8 used encryption with the max protocol set as SMB3. The connection could lose the requirement for signing and encrypting to any DFS redirects, allowing an attacker to read or alter the contents of the connection via a man-in-the-middle attack.
A flaw was found in the way samba client used encryption with the max protocol set as SMB3. The connection could lose the requirement for signing and encrypting to any DFS redirects, allowing an attacker to read or alter the contents of the connection via a man-in-the-middle attack.
Statement: The samba4 package in Red Hat Enterprise Linux 6, is a tech preview and by default uses the SMB1 prot
Debian
CVE-2017-12151: samba - A flaw was found in the way samba client before samba 4.4.16, samba 4.5.14 and s...
vendor_debian·2017·CVSS 7.4
CVE-2017-12151 [HIGH] CVE-2017-12151: samba - A flaw was found in the way samba client before samba 4.4.16, samba 4.5.14 and s...
A flaw was found in the way samba client before samba 4.4.16, samba 4.5.14 and samba 4.6.8 used encryption with the max protocol set as SMB3. The connection could lose the requirement for signing and encrypting to any DFS redirects, allowing an attacker to read or alter the contents of the connection via a man-in-the-middle attack.
Scope: local
bookworm: resolved (fixed in 2:4.6.7+dfsg-2)
bullseye: resolved (fixed in 2:4.6.7+dfsg-2)
forky: resolved (fixed in 2:4.6.7+dfsg-2)
sid: resolved (fixed in 2:4.6.7+dfsg-2)
trixie: resolved (fixed in 2:4.6.7+dfsg-2)
Debian
CVE-2017-15086: samba - It was discovered that the fix for CVE-2017-12151 was not properly shipped in er...
vendor_debian·2017·CVSS 7.4
CVE-2017-15086 [HIGH] CVE-2017-15086: samba - It was discovered that the fix for CVE-2017-12151 was not properly shipped in er...
It was discovered that the fix for CVE-2017-12151 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHEL 6.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-15086 samba: SMB2 connections don't keep encryption across DFS redirects (incomplete fix of CVE-2017-12151)
bugzilla·2017-10-24·CVSS 7.4
CVE-2017-15086 [HIGH] CVE-2017-15086 samba: SMB2 connections don't keep encryption across DFS redirects (incomplete fix of CVE-2017-12151)
CVE-2017-15086 samba: SMB2 connections don't keep encryption across DFS redirects (incomplete fix of CVE-2017-12151)
It was found that Red Hat Gluster Storage 3 for RHEL-6 shipped incomplete fix for CVE-2017-12151.
Discussion:
This issue has been addressed in the following products:
Red Hat Gluster Storage 3.3 for RHEL 6
Via RHSA-2017:3110 https://access.redhat.com/errata/RHSA-2017:3110
Bugzilla
CVE-2017-12151 CVE-2017-12150 CVE-2017-12163 samba: Multiple security flaws [fedora-all]
bugzilla·2017-09-20·CVSS 7.4
CVE-2017-12151 [HIGH] CVE-2017-12151 CVE-2017-12150 CVE-2017-12163 samba: Multiple security flaws [fedora-all]
CVE-2017-12151 CVE-2017-12150 CVE-2017-12163 samba: Multiple security flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple support
Bugzilla
CVE-2017-12151 samba: SMB2 connections don't keep encryption across DFS redirects
bugzilla·2017-09-04·CVSS 7.4
CVE-2017-12151 [HIGH] CVE-2017-12151 samba: SMB2 connections don't keep encryption across DFS redirects
CVE-2017-12151 samba: SMB2 connections don't keep encryption across DFS redirects
Client command line tools like 'smbclient' as well as applications using
'libsmbclient' library have support for required encryption. This is activated
by the '-e|--encrypt' command line option or the
smbc_setOptionSmbEncryptionLevel() library call.
By default, only SMB1 is used in order to do connections to a server,
as the effective default for "client max protocol" smb.conf option
as well for the "-m|--max-protocol=" command line option is "NT1".
If the original client connection used encryption, following DFS
redirects to another server also enforce encryption. This is
important as these redirects are transparent to the application.
In case "SMB3", "SMB3_00", "SMB3_02", "SMB3_10" or "SMB3_11" is
used
http://www.securityfocus.com/bid/100917http://www.securitytracker.com/id/1039401https://access.redhat.com/errata/RHSA-2017:2790https://access.redhat.com/errata/RHSA-2017:2858https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-12151https://security.netapp.com/advisory/ntap-20170921-0001/https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03817en_ushttps://www.debian.org/security/2017/dsa-3983https://www.samba.org/samba/security/CVE-2017-12151.htmlhttp://www.securityfocus.com/bid/100917http://www.securitytracker.com/id/1039401https://access.redhat.com/errata/RHSA-2017:2790https://access.redhat.com/errata/RHSA-2017:2858https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-12151https://security.netapp.com/advisory/ntap-20170921-0001/https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03817en_ushttps://www.debian.org/security/2017/dsa-3983https://www.samba.org/samba/security/CVE-2017-12151.html
2018-07-27
Published