CVE Vulnerabilities

CVE-2007-3843

Published: Aug 09, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The Linux kernel before 2.6.23-rc1 checks the wrong global variable for the CIFS sec mount option, which might allow remote attackers to spoof CIFS network traffic that the client configured for security signatures, as demonstrated by lack of signing despite sec=ntlmv2i in a SetupAndX request.

Affected Software

NameVendorStart VersionEnd Version
Linux_kernelLinux*2.6.22 (including)
Red Hat Enterprise Linux 4RedHatkernel-0:2.6.9-55.0.12.EL*
Red Hat Enterprise Linux 5RedHatkernel-0:2.6.18-8.1.10.el5*
Linux-source-2.6.20Ubuntufeisty*

References