CVE Vulnerabilities

CVE-2007-3843

Published: Aug 09, 2007 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

The Linux kernel before 2.6.23-rc1 checks the wrong global variable for the CIFS sec mount option, which might allow remote attackers to spoof CIFS network traffic that the client configured for security signatures, as demonstrated by lack of signing despite sec=ntlmv2i in a SetupAndX request.

Affected Software

Name Vendor Start Version End Version
Linux_kernel Linux * 2.6.22 (including)
Red Hat Enterprise Linux 4 RedHat kernel-0:2.6.9-55.0.12.EL *
Red Hat Enterprise Linux 5 RedHat kernel-0:2.6.18-8.1.10.el5 *
Linux-source-2.6.20 Ubuntu feisty *

References