CVE-2016-2112: Medium severity samba vulnerability
The bundled LDAP client library in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not recognize the "client ldap sasl wrapping" setting, which allows man-in-the-middle attackers to perform LDAP protocol-downgrade attacks by modifying the client-server data stream.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2112?
CVE-2016-2112 has been rated as a high severity vulnerability due to its potential for man-in-the-middle attacks.
How do I fix CVE-2016-2112?
To mitigate CVE-2016-2112, upgrade your Samba installation to version 4.2.11, 4.3.8, or 4.4.2 or later.
Which versions of Samba are affected by CVE-2016-2112?
CVE-2016-2112 affects Samba versions 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2.
What kind of attack does CVE-2016-2112 allow?
CVE-2016-2112 allows attackers to perform LDAP protocol-downgrade attacks by modifying the client-server data stream.
Is there a workaround for CVE-2016-2112 if I cannot update Samba?
If you cannot update, you may temporarily restrict access to LDAP services to trusted networks to reduce exposure to CVE-2016-2112.