Man-in-the-middle attack in Oracle products - CVE-2016-2111

 

Man-in-the-middle attack in Oracle products - CVE-2016-2111

Published: July 29, 2016 / Updated: November 22, 2018


Vulnerability identifier: #VU236
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-2111
CWE-ID: CWE-290
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to to conduct spoofing attacks.

The vulnerability exists due to an error in the NETLOGON service when a Domain Controller is configured. A remote unauthenticated attacker can conduct spoofing attacks by using a specially crafted application to connect to another domain joined system and access session-related information of the spoofed computer.

Successful exploitation of this vulnerability may result in disclosure of user information.


Affected software

Samba
Oracle Linux
Oracle Solaris
Amazon Linux AMI
Arch Linux
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Server from RHUI
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
SUSE Linux
Ubuntu
Slackware Linux
Fedora
ProtecTIER Entry Edition (PID 5639-PTC) - TS7610 / TS7620
ProtecTIER Appliance Edition (PID 5639-PTB) - TS7650AP1
ProtecTIER Enterprise Edition (PID 5639-PTA) - TS7650G
Red Hat Gluster Storage Server for On-premise
HP-UX Common Internet File System (CIFS)
libtevent (Red Hat package)
evolution-mapi (Red Hat package)
openchange (Red Hat package)
libldb (Red Hat package)
libtdb (Red Hat package)
sssd (Red Hat package)
libtalloc (Red Hat package)
samba (Red Hat package)
samba3x (Red Hat package)
samba4 (Red Hat package)
samba

How to mitigate CVE-2016-2111

Install Samba 4.4.2, 4.3.8 and 4.2.11

HP-UX Common Internet File System (CIFS) - update to A.03.02.07
libtevent (Red Hat package) - addressed in versions 0.9.26-1.el7_1, 0.9.26-1.el6rhs, 0.9.26-1.el7rhgs
evolution-mapi (Red Hat package) - update to 0.28.3-8.el6_2
openchange (Red Hat package) - addressed in versions 1.0-1.el6_2, 1.0-5.el6_4, 1.0-7.el6_5, 1.0-7.el6_6
libldb (Red Hat package) - addressed in versions 1.1.24-1.el6rhs, 1.1.24-1.el7rhgs, 1.1.25-1.el7_1, 1.1.25-2.el6_2, 1.1.25-2.el6_4, 1.1.25-2.el6_5, 1.1.25-2.el6_6
libtdb (Red Hat package) - addressed in versions 1.3.8-1.el7_1, 1.3.8-1.el6rhs, 1.3.8-1.el7rhgs
sssd (Red Hat package) - update to 1.9.2-82.12.el6_4
libtalloc (Red Hat package) - addressed in versions 2.1.5-1.el7_1, 2.1.5-1.el6rhs, 2.1.5-1.el7rhgs
samba (Red Hat package) - addressed in versions 3.0.33-3.30.el5_6, 3.0.33-3.37.el4, 3.0.33-3.40.el5_9, 3.0.33-3.41.el5_11, 3.6.23-30.el6_2, 3.6.23-30.el6_4, 3.6.23-30.el6_5, 3.6.23-30.el6_6, 4.2.10-5.el7_1, 4.2.11-2.el6rhs, 4.2.11-2.el7rhgs
samba3x (Red Hat package) - addressed in versions 3.6.23-12.el5_6, 3.6.23-12.el5_9, 3.6.23-12.el5_11
samba4 (Red Hat package) - addressed in versions 4.2.10-6.el6_2, 4.2.10-6.el6_4, 4.2.10-6.el6_5, 4.2.10-6.el6_6
samba - addressed in versions 4.2.11-0.fc22, 4.3.8-0.fc23, 4.4.2-1.fc24

External References

Related Security Bulletins