CVE Vulnerabilities

CVE-2016-2118

Published: Apr 12, 2016 | Modified: Aug 29, 2022
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The MS-SAMR and MS-LSAD protocol implementations in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 mishandle DCERPC connections, which allows man-in-the-middle attackers to perform protocol-downgrade attacks and impersonate users by modifying the client-server data stream, aka BADLOCK.

Affected Software

Name Vendor Start Version End Version
Samba Samba 3.6.0 (including) 4.2.10 (excluding)
Samba Samba 4.3.0 (including) 4.3.7 (excluding)
Samba Samba 4.4.0 (including) 4.4.1 (excluding)

References