Man-in-the-middle attack in Samba - CVE-2016-2118
Published: July 29, 2016 / Updated: November 22, 2018
Vulnerability identifier: #VU241
CSH Severity: High
CVSS v4: 7.3 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-2118
CWE-ID: CWE-300
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain elevated privileges on the system.
The vulnerability exists due to the acceptance of inadequate authentication levels by the Microsoft Security Account Manager (SAM) and Local Security Authority (Domain Policy) (LSAD) remote protocols. A remote attacker can gain elevated privileges on the system by using man-in-the-middle techniques to impersonate an authenticated user against the SAMR or LSAD service and gain access to the Security Account Manager (SAM) database.
Successful exploitation of this vulnerability may result in disclosere of sytem information.
The vulnerability exists due to the acceptance of inadequate authentication levels by the Microsoft Security Account Manager (SAM) and Local Security Authority (Domain Policy) (LSAD) remote protocols. A remote attacker can gain elevated privileges on the system by using man-in-the-middle techniques to impersonate an authenticated user against the SAMR or LSAD service and gain access to the Security Account Manager (SAM) database.
Successful exploitation of this vulnerability may result in disclosere of sytem information.
Affected software
Samba
ProtecTIER Entry Edition (PID 5639-PTC) - TS7610 / TS7620
ProtecTIER Appliance Edition (PID 5639-PTB) - TS7650AP1
ProtecTIER Enterprise Edition (PID 5639-PTA) - TS7650G
HP Systems Insight Manager
Arch Linux
Amazon Linux AMI
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Server from RHUI
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
SUSE Linux
Ubuntu
Slackware Linux
Fedora
Red Hat Gluster Storage Server for On-premise
HP-UX Common Internet File System (CIFS)
libtevent (Red Hat package)
evolution-mapi (Red Hat package)
openchange (Red Hat package)
libldb (Red Hat package)
libtdb (Red Hat package)
sssd (Red Hat package)
libtalloc (Red Hat package)
samba (Red Hat package)
samba3x (Red Hat package)
samba4 (Red Hat package)
samba
ProtecTIER Entry Edition (PID 5639-PTC) - TS7610 / TS7620
ProtecTIER Appliance Edition (PID 5639-PTB) - TS7650AP1
ProtecTIER Enterprise Edition (PID 5639-PTA) - TS7650G
HP Systems Insight Manager
Arch Linux
Amazon Linux AMI
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Server from RHUI
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
SUSE Linux
Ubuntu
Slackware Linux
Fedora
Red Hat Gluster Storage Server for On-premise
HP-UX Common Internet File System (CIFS)
libtevent (Red Hat package)
evolution-mapi (Red Hat package)
openchange (Red Hat package)
libldb (Red Hat package)
libtdb (Red Hat package)
sssd (Red Hat package)
libtalloc (Red Hat package)
samba (Red Hat package)
samba3x (Red Hat package)
samba4 (Red Hat package)
samba
How to mitigate CVE-2016-2118
Install Samba 4.4.2, 4.3.8 and 4.2.11
HP-UX Common Internet File System (CIFS) - update to A.03.02.07
libtevent (Red Hat package) - addressed in versions 0.9.26-1.el7_1, 0.9.26-1.el6rhs, 0.9.26-1.el7rhgs
evolution-mapi (Red Hat package) - update to 0.28.3-8.el6_2
openchange (Red Hat package) - addressed in versions 1.0-1.el6_2, 1.0-5.el6_4, 1.0-7.el6_5, 1.0-7.el6_6
libldb (Red Hat package) - addressed in versions 1.1.24-1.el6rhs, 1.1.24-1.el7rhgs, 1.1.25-1.el7_1, 1.1.25-2.el6_2, 1.1.25-2.el6_4, 1.1.25-2.el6_5, 1.1.25-2.el6_6
libtdb (Red Hat package) - addressed in versions 1.3.8-1.el7_1, 1.3.8-1.el6rhs, 1.3.8-1.el7rhgs
sssd (Red Hat package) - update to 1.9.2-82.12.el6_4
libtalloc (Red Hat package) - addressed in versions 2.1.5-1.el7_1, 2.1.5-1.el6rhs, 2.1.5-1.el7rhgs
samba (Red Hat package) - addressed in versions 3.0.33-3.30.el5_6, 3.0.33-3.37.el4, 3.0.33-3.40.el5_9, 3.0.33-3.41.el5_11, 3.6.23-30.el6_2, 3.6.23-30.el6_4, 3.6.23-30.el6_5, 3.6.23-30.el6_6, 4.2.10-5.el7_1, 4.2.11-2.el6rhs, 4.2.11-2.el7rhgs
samba3x (Red Hat package) - addressed in versions 3.6.23-12.el5_6, 3.6.23-12.el5_9, 3.6.23-12.el5_11
samba4 (Red Hat package) - addressed in versions 4.2.10-6.el6_2, 4.2.10-6.el6_4, 4.2.10-6.el6_5, 4.2.10-6.el6_6
samba - addressed in versions 4.2.11-0.fc22, 4.3.8-0.fc23, 4.4.2-1.fc24
libtevent (Red Hat package) - addressed in versions 0.9.26-1.el7_1, 0.9.26-1.el6rhs, 0.9.26-1.el7rhgs
evolution-mapi (Red Hat package) - update to 0.28.3-8.el6_2
openchange (Red Hat package) - addressed in versions 1.0-1.el6_2, 1.0-5.el6_4, 1.0-7.el6_5, 1.0-7.el6_6
libldb (Red Hat package) - addressed in versions 1.1.24-1.el6rhs, 1.1.24-1.el7rhgs, 1.1.25-1.el7_1, 1.1.25-2.el6_2, 1.1.25-2.el6_4, 1.1.25-2.el6_5, 1.1.25-2.el6_6
libtdb (Red Hat package) - addressed in versions 1.3.8-1.el7_1, 1.3.8-1.el6rhs, 1.3.8-1.el7rhgs
sssd (Red Hat package) - update to 1.9.2-82.12.el6_4
libtalloc (Red Hat package) - addressed in versions 2.1.5-1.el7_1, 2.1.5-1.el6rhs, 2.1.5-1.el7rhgs
samba (Red Hat package) - addressed in versions 3.0.33-3.30.el5_6, 3.0.33-3.37.el4, 3.0.33-3.40.el5_9, 3.0.33-3.41.el5_11, 3.6.23-30.el6_2, 3.6.23-30.el6_4, 3.6.23-30.el6_5, 3.6.23-30.el6_6, 4.2.10-5.el7_1, 4.2.11-2.el6rhs, 4.2.11-2.el7rhgs
samba3x (Red Hat package) - addressed in versions 3.6.23-12.el5_6, 3.6.23-12.el5_9, 3.6.23-12.el5_11
samba4 (Red Hat package) - addressed in versions 4.2.10-6.el6_2, 4.2.10-6.el6_4, 4.2.10-6.el6_5, 4.2.10-6.el6_6
samba - addressed in versions 4.2.11-0.fc22, 4.3.8-0.fc23, 4.4.2-1.fc24
External References
Related Security Bulletins
- Ubuntu update for Samba
- Ubuntu update for Samba
- Ubuntu update for Samba
- Ubuntu update for libsoup
- Ubuntu update for Samba
- Arch Linux update for samba
- Slackware Linux update for samba
- SUSE Linux update for samba
- OpenSUSE Linux update for samba
- SUSE Linux update for samba
- SUSE Linux update for samba
- SUSE Linux update for samba
- Amazon Linux AMI update for samba
- Man-in-the-middle attack in HPE Systems Insight Manager
- Multiple vulnerabilities in HPE HP-UX running CIFS Server (Samba)
- Multiple vulnerabilities in IBM ProtecTIER
- Fedora 24 update for samba
- Fedora 23 update for samba
- Fedora 22 update for samba
- Red Hat Enterprise Linux 5 update for samba3x
- Red Hat Enterprise Linux 6 update for samba4
- Red Hat Enterprise Linux 6 update for samba
- Red Hat Enterprise Linux 7 update for samba
- Red Hat Gluster Storage 3 update for samba
- Red Hat Enterprise Linux 5 update for samba3x
- Red Hat Enterprise Linux 4 ExtendedLifecycle Support update for samba
- Red Hat Enterprise Linux 5 update for samba
- Red Hat Enterprise Linux 5 update for samba