CVE Vulnerabilities

CVE-2016-2113

Published: Apr 25, 2016 | Modified: Dec 31, 2016
CVSS 3.x
7.4
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V3
Ubuntu
MEDIUM

Samba 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not verify X.509 certificates from TLS servers, which allows man-in-the-middle attackers to spoof LDAPS and HTTPS servers and obtain sensitive information via a crafted certificate.

Affected Software

Name Vendor Start Version End Version
Samba Samba 4.0.0 (including) 4.0.0 (including)
Samba Samba 4.0.1 (including) 4.0.1 (including)
Samba Samba 4.0.2 (including) 4.0.2 (including)
Samba Samba 4.0.3 (including) 4.0.3 (including)
Samba Samba 4.0.4 (including) 4.0.4 (including)
Samba Samba 4.0.5 (including) 4.0.5 (including)
Samba Samba 4.0.6 (including) 4.0.6 (including)
Samba Samba 4.0.7 (including) 4.0.7 (including)
Samba Samba 4.0.8 (including) 4.0.8 (including)
Samba Samba 4.0.9 (including) 4.0.9 (including)
Samba Samba 4.0.10 (including) 4.0.10 (including)
Samba Samba 4.0.11 (including) 4.0.11 (including)
Samba Samba 4.0.12 (including) 4.0.12 (including)
Samba Samba 4.0.13 (including) 4.0.13 (including)
Samba Samba 4.0.14 (including) 4.0.14 (including)
Samba Samba 4.0.15 (including) 4.0.15 (including)
Samba Samba 4.0.16 (including) 4.0.16 (including)
Samba Samba 4.0.17 (including) 4.0.17 (including)
Samba Samba 4.0.18 (including) 4.0.18 (including)
Samba Samba 4.0.19 (including) 4.0.19 (including)
Samba Samba 4.0.20 (including) 4.0.20 (including)
Samba Samba 4.0.21 (including) 4.0.21 (including)
Samba Samba 4.0.22 (including) 4.0.22 (including)
Samba Samba 4.0.23 (including) 4.0.23 (including)
Samba Samba 4.0.24 (including) 4.0.24 (including)
Samba Samba 4.0.25 (including) 4.0.25 (including)
Samba Samba 4.0.26 (including) 4.0.26 (including)
Samba Samba 4.1.0 (including) 4.1.0 (including)
Samba Samba 4.1.1 (including) 4.1.1 (including)
Samba Samba 4.1.2 (including) 4.1.2 (including)
Samba Samba 4.1.3 (including) 4.1.3 (including)
Samba Samba 4.1.4 (including) 4.1.4 (including)
Samba Samba 4.1.5 (including) 4.1.5 (including)
Samba Samba 4.1.6 (including) 4.1.6 (including)
Samba Samba 4.1.7 (including) 4.1.7 (including)
Samba Samba 4.1.8 (including) 4.1.8 (including)
Samba Samba 4.1.9 (including) 4.1.9 (including)
Samba Samba 4.1.10 (including) 4.1.10 (including)
Samba Samba 4.1.11 (including) 4.1.11 (including)
Samba Samba 4.1.12 (including) 4.1.12 (including)
Samba Samba 4.1.13 (including) 4.1.13 (including)
Samba Samba 4.1.14 (including) 4.1.14 (including)
Samba Samba 4.1.15 (including) 4.1.15 (including)
Samba Samba 4.1.16 (including) 4.1.16 (including)
Samba Samba 4.1.17 (including) 4.1.17 (including)
Samba Samba 4.1.18 (including) 4.1.18 (including)
Samba Samba 4.1.19 (including) 4.1.19 (including)
Samba Samba 4.1.20 (including) 4.1.20 (including)
Samba Samba 4.1.21 (including) 4.1.21 (including)
Samba Samba 4.1.22 (including) 4.1.22 (including)
Samba Samba 4.1.23 (including) 4.1.23 (including)
Samba Samba 4.2.0-rc1 (including) 4.2.0-rc1 (including)
Samba Samba 4.2.0-rc2 (including) 4.2.0-rc2 (including)
Samba Samba 4.2.0-rc3 (including) 4.2.0-rc3 (including)
Samba Samba 4.2.0-rc4 (including) 4.2.0-rc4 (including)
Samba Samba 4.2.1 (including) 4.2.1 (including)
Samba Samba 4.2.2 (including) 4.2.2 (including)
Samba Samba 4.2.3 (including) 4.2.3 (including)
Samba Samba 4.2.4 (including) 4.2.4 (including)
Samba Samba 4.2.5 (including) 4.2.5 (including)
Samba Samba 4.2.6 (including) 4.2.6 (including)
Samba Samba 4.2.7 (including) 4.2.7 (including)
Samba Samba 4.2.8 (including) 4.2.8 (including)
Samba Samba 4.2.9 (including) 4.2.9 (including)
Samba Samba 4.3.0 (including) 4.3.0 (including)
Samba Samba 4.3.1 (including) 4.3.1 (including)
Samba Samba 4.3.2 (including) 4.3.2 (including)
Samba Samba 4.3.3 (including) 4.3.3 (including)
Samba Samba 4.3.4 (including) 4.3.4 (including)
Samba Samba 4.3.5 (including) 4.3.5 (including)
Samba Samba 4.3.6 (including) 4.3.6 (including)
Samba Samba 4.4.0 (including) 4.4.0 (including)
Red Hat Enterprise Linux 6 RedHat ipa-0:3.0.0-47.el6_7.2 *
Red Hat Enterprise Linux 6 RedHat libldb-0:1.1.25-2.el6_7 *
Red Hat Enterprise Linux 6 RedHat libtalloc-0:2.1.5-1.el6_7 *
Red Hat Enterprise Linux 6 RedHat libtdb-0:1.3.8-1.el6_7 *
Red Hat Enterprise Linux 6 RedHat libtevent-0:0.9.26-2.el6_7 *
Red Hat Enterprise Linux 6 RedHat openchange-0:1.0-7.el6_7 *
Red Hat Enterprise Linux 6 RedHat samba4-0:4.2.10-6.el6_7 *
Red Hat Enterprise Linux 6.2 Advanced Update Support RedHat evolution-mapi-0:0.28.3-8.el6_2 *
Red Hat Enterprise Linux 6.2 Advanced Update Support RedHat libldb-0:1.1.25-2.el6_2 *
Red Hat Enterprise Linux 6.2 Advanced Update Support RedHat openchange-0:1.0-1.el6_2 *
Red Hat Enterprise Linux 6.2 Advanced Update Support RedHat samba4-0:4.2.10-6.el6_2 *
Red Hat Enterprise Linux 6.2 Advanced Update Support RedHat sssd-0:1.5.1-66.el6_2.5 *
Red Hat Enterprise Linux 6.4 Advanced Update Support RedHat ipa-0:3.0.0-26.el6_4.5 *
Red Hat Enterprise Linux 6.4 Advanced Update Support RedHat libldb-0:1.1.25-2.el6_4 *
Red Hat Enterprise Linux 6.4 Advanced Update Support RedHat openchange-0:1.0-5.el6_4 *
Red Hat Enterprise Linux 6.4 Advanced Update Support RedHat samba4-0:4.2.10-6.el6_4 *
Red Hat Enterprise Linux 6.4 Advanced Update Support RedHat sssd-0:1.9.2-82.12.el6_4 *
Red Hat Enterprise Linux 6.5 Advanced Update Support RedHat ipa-0:3.0.0-37.el6_5.1 *
Red Hat Enterprise Linux 6.5 Advanced Update Support RedHat libldb-0:1.1.25-2.el6_5 *
Red Hat Enterprise Linux 6.5 Advanced Update Support RedHat openchange-0:1.0-7.el6_5 *
Red Hat Enterprise Linux 6.5 Advanced Update Support RedHat samba4-0:4.2.10-6.el6_5 *
Red Hat Enterprise Linux 6.5 Advanced Update Support RedHat sssd-0:1.9.2-129.el6_5.7 *
Red Hat Enterprise Linux 6.6 Extended Update Support RedHat ipa-0:3.0.0-42.el6_6.1 *
Red Hat Enterprise Linux 6.6 Extended Update Support RedHat libldb-0:1.1.25-2.el6_6 *
Red Hat Enterprise Linux 6.6 Extended Update Support RedHat openchange-0:1.0-7.el6_6 *
Red Hat Enterprise Linux 6.6 Extended Update Support RedHat samba4-0:4.2.10-6.el6_6 *
Red Hat Enterprise Linux 7 RedHat ipa-0:4.2.0-15.el7_2.6.1 *
Red Hat Enterprise Linux 7 RedHat libldb-0:1.1.25-1.el7_2 *
Red Hat Enterprise Linux 7 RedHat libtalloc-0:2.1.5-1.el7_2 *
Red Hat Enterprise Linux 7 RedHat libtdb-0:1.3.8-1.el7_2 *
Red Hat Enterprise Linux 7 RedHat libtevent-0:0.9.26-1.el7_2 *
Red Hat Enterprise Linux 7 RedHat openchange-0:2.0-10.el7_2 *
Red Hat Enterprise Linux 7 RedHat samba-0:4.2.10-6.el7_2 *
Red Hat Enterprise Linux 7.1 Extended Update Support RedHat ipa-0:4.1.0-18.el7_1.6 *
Red Hat Enterprise Linux 7.1 Extended Update Support RedHat libldb-0:1.1.25-1.el7_1 *
Red Hat Enterprise Linux 7.1 Extended Update Support RedHat libtalloc-0:2.1.5-1.ael7b_1 *
Red Hat Enterprise Linux 7.1 Extended Update Support RedHat libtdb-0:1.3.8-1.el7_1 *
Red Hat Enterprise Linux 7.1 Extended Update Support RedHat libtevent-0:0.9.26-1.el7_1 *
Red Hat Enterprise Linux 7.1 Extended Update Support RedHat openchange-0:2.0-4.ael7b_1.1 *
Red Hat Enterprise Linux 7.1 Extended Update Support RedHat samba-0:4.2.10-5.ael7b_1 *
Red Hat Gluster Storage 3.1 for RHEL 6 RedHat libldb-0:1.1.24-1.el6rhs *
Red Hat Gluster Storage 3.1 for RHEL 6 RedHat libtalloc-0:2.1.5-1.el6rhs *
Red Hat Gluster Storage 3.1 for RHEL 6 RedHat libtdb-0:1.3.8-1.el6rhs *
Red Hat Gluster Storage 3.1 for RHEL 6 RedHat libtevent-0:0.9.26-1.el6rhs *
Red Hat Gluster Storage 3.1 for RHEL 6 RedHat samba-0:4.2.11-2.el6rhs *
Red Hat Gluster Storage 3.1 for RHEL 7 RedHat libldb-0:1.1.24-1.el7rhgs *
Red Hat Gluster Storage 3.1 for RHEL 7 RedHat libtalloc-0:2.1.5-1.el7rhgs *
Red Hat Gluster Storage 3.1 for RHEL 7 RedHat libtdb-0:1.3.8-1.el7rhgs *
Red Hat Gluster Storage 3.1 for RHEL 7 RedHat libtevent-0:0.9.26-1.el7rhgs *
Red Hat Gluster Storage 3.1 for RHEL 7 RedHat samba-0:4.2.11-2.el7rhgs *
Samba Ubuntu devel *
Samba Ubuntu trusty *
Samba Ubuntu upstream *
Samba Ubuntu wily *
Samba Ubuntu xenial *
Samba Ubuntu yakkety *
Samba Ubuntu zesty *
Samba4 Ubuntu precise *

References