First published: Mon Apr 25 2016(Updated: )
The bundled LDAP client library in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not recognize the "client ldap sasl wrapping" setting, which allows man-in-the-middle attackers to perform LDAP protocol-downgrade attacks by modifying the client-server data stream.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samba | =3.0.0 | |
Samba | =3.0.1 | |
Samba | =3.0.2 | |
Samba | =3.0.2-a | |
Samba | =3.0.2a | |
Samba | =3.0.3 | |
Samba | =3.0.4 | |
Samba | =3.0.4-rc1 | |
Samba | =3.0.5 | |
Samba | =3.0.6 | |
Samba | =3.0.7 | |
Samba | =3.0.8 | |
Samba | =3.0.9 | |
Samba | =3.0.10 | |
Samba | =3.0.11 | |
Samba | =3.0.12 | |
Samba | =3.0.13 | |
Samba | =3.0.14 | |
Samba | =3.0.14-a | |
Samba | =3.0.14a | |
Samba | =3.0.15 | |
Samba | =3.0.16 | |
Samba | =3.0.17 | |
Samba | =3.0.18 | |
Samba | =3.0.19 | |
Samba | =3.0.20 | |
Samba | =3.0.20-a | |
Samba | =3.0.20-b | |
Samba | =3.0.20a | |
Samba | =3.0.20b | |
Samba | =3.0.21 | |
Samba | =3.0.21-a | |
Samba | =3.0.21-b | |
Samba | =3.0.21-c | |
Samba | =3.0.21a | |
Samba | =3.0.21b | |
Samba | =3.0.21c | |
Samba | =3.0.22 | |
Samba | =3.0.23 | |
Samba | =3.0.23-a | |
Samba | =3.0.23-b | |
Samba | =3.0.23-c | |
Samba | =3.0.23-d | |
Samba | =3.0.23a | |
Samba | =3.0.23b | |
Samba | =3.0.23c | |
Samba | =3.0.23d | |
Samba | =3.0.24 | |
Samba | =3.0.25 | |
Samba | =3.0.25-a | |
Samba | =3.0.25-b | |
Samba | =3.0.25-c | |
Samba | =3.0.25-pre1 | |
Samba | =3.0.25-pre2 | |
Samba | =3.0.25-rc1 | |
Samba | =3.0.25-rc2 | |
Samba | =3.0.25-rc3 | |
Samba | =3.0.25a | |
Samba | =3.0.25b | |
Samba | =3.0.25c | |
Samba | =3.0.26 | |
Samba | =3.0.26-a | |
Samba | =3.0.26a | |
Samba | =3.0.27 | |
Samba | =3.0.27-a | |
Samba | =3.0.28 | |
Samba | =3.0.28-a | |
Samba | =3.0.29 | |
Samba | =3.0.30 | |
Samba | =3.0.31 | |
Samba | =3.0.32 | |
Samba | =3.0.33 | |
Samba | =3.0.34 | |
Samba | =3.0.35 | |
Samba | =3.0.36 | |
Samba | =3.0.37 | |
Samba | =3.2.0 | |
Samba | =3.2.1 | |
Samba | =3.2.2 | |
Samba | =3.2.3 | |
Samba | =3.2.4 | |
Samba | =3.2.5 | |
Samba | =3.2.6 | |
Samba | =3.2.7 | |
Samba | =3.2.8 | |
Samba | =3.2.9 | |
Samba | =3.2.10 | |
Samba | =3.2.11 | |
Samba | =3.2.12 | |
Samba | =3.2.13 | |
Samba | =3.2.14 | |
Samba | =3.2.15 | |
Samba | =3.3.0 | |
Samba | =3.3.1 | |
Samba | =3.3.2 | |
Samba | =3.3.3 | |
Samba | =3.3.4 | |
Samba | =3.3.5 | |
Samba | =3.3.6 | |
Samba | =3.3.7 | |
Samba | =3.3.8 | |
Samba | =3.3.9 | |
Samba | =3.3.10 | |
Samba | =3.3.11 | |
Samba | =3.3.12 | |
Samba | =3.3.13 | |
Samba | =3.3.14 | |
Samba | =3.3.15 | |
Samba | =3.3.16 | |
Samba | =3.4.0 | |
Samba | =3.4.1 | |
Samba | =3.4.2 | |
Samba | =3.4.3 | |
Samba | =3.4.4 | |
Samba | =3.4.5 | |
Samba | =3.4.6 | |
Samba | =3.4.7 | |
Samba | =3.4.8 | |
Samba | =3.4.9 | |
Samba | =3.4.10 | |
Samba | =3.4.11 | |
Samba | =3.4.12 | |
Samba | =3.4.13 | |
Samba | =3.4.14 | |
Samba | =3.4.15 | |
Samba | =3.4.16 | |
Samba | =3.4.17 | |
Samba | =3.5.0 | |
Samba | =3.5.1 | |
Samba | =3.5.2 | |
Samba | =3.5.3 | |
Samba | =3.5.4 | |
Samba | =3.5.5 | |
Samba | =3.5.6 | |
Samba | =3.5.7 | |
Samba | =3.5.8 | |
Samba | =3.5.9 | |
Samba | =3.5.10 | |
Samba | =3.5.11 | |
Samba | =3.5.12 | |
Samba | =3.5.13 | |
Samba | =3.5.14 | |
Samba | =3.5.15 | |
Samba | =3.5.16 | |
Samba | =3.5.17 | |
Samba | =3.5.18 | |
Samba | =3.5.19 | |
Samba | =3.5.20 | |
Samba | =3.5.21 | |
Samba | =3.5.22 | |
Samba | =3.6.0 | |
Samba | =3.6.1 | |
Samba | =3.6.2 | |
Samba | =3.6.3 | |
Samba | =3.6.4 | |
Samba | =3.6.5 | |
Samba | =3.6.6 | |
Samba | =3.6.7 | |
Samba | =3.6.8 | |
Samba | =3.6.9 | |
Samba | =3.6.10 | |
Samba | =3.6.11 | |
Samba | =3.6.12 | |
Samba | =3.6.13 | |
Samba | =3.6.14 | |
Samba | =3.6.15 | |
Samba | =3.6.16 | |
Samba | =3.6.17 | |
Samba | =3.6.18 | |
Samba | =3.6.19 | |
Samba | =3.6.20 | |
Samba | =3.6.21 | |
Samba | =3.6.22 | |
Samba | =3.6.23 | |
Samba | =3.6.24 | |
Samba | =3.6.25 | |
Samba | =4.0.0 | |
Samba | =4.0.1 | |
Samba | =4.0.2 | |
Samba | =4.0.3 | |
Samba | =4.0.4 | |
Samba | =4.0.5 | |
Samba | =4.0.6 | |
Samba | =4.0.7 | |
Samba | =4.0.8 | |
Samba | =4.0.9 | |
Samba | =4.0.10 | |
Samba | =4.0.11 | |
Samba | =4.0.12 | |
Samba | =4.0.13 | |
Samba | =4.0.14 | |
Samba | =4.0.15 | |
Samba | =4.0.16 | |
Samba | =4.0.17 | |
Samba | =4.0.18 | |
Samba | =4.0.19 | |
Samba | =4.0.20 | |
Samba | =4.0.21 | |
Samba | =4.0.22 | |
Samba | =4.0.23 | |
Samba | =4.0.24 | |
Samba | =4.0.25 | |
Samba | =4.0.26 | |
Samba | =4.1.0 | |
Samba | =4.1.1 | |
Samba | =4.1.2 | |
Samba | =4.1.3 | |
Samba | =4.1.4 | |
Samba | =4.1.5 | |
Samba | =4.1.6 | |
Samba | =4.1.7 | |
Samba | =4.1.8 | |
Samba | =4.1.9 | |
Samba | =4.1.10 | |
Samba | =4.1.11 | |
Samba | =4.1.12 | |
Samba | =4.1.13 | |
Samba | =4.1.14 | |
Samba | =4.1.15 | |
Samba | =4.1.16 | |
Samba | =4.1.17 | |
Samba | =4.1.18 | |
Samba | =4.1.19 | |
Samba | =4.1.20 | |
Samba | =4.1.21 | |
Samba | =4.1.22 | |
Samba | =4.1.23 | |
Samba | =4.2.0-rc1 | |
Samba | =4.2.0-rc2 | |
Samba | =4.2.0-rc3 | |
Samba | =4.2.0-rc4 | |
Samba | =4.2.1 | |
Samba | =4.2.2 | |
Samba | =4.2.3 | |
Samba | =4.2.4 | |
Samba | =4.2.5 | |
Samba | =4.2.6 | |
Samba | =4.2.7 | |
Samba | =4.2.8 | |
Samba | =4.2.9 | |
Samba | =4.3.0 | |
Samba | =4.3.1 | |
Samba | =4.3.2 | |
Samba | =4.3.3 | |
Samba | =4.3.4 | |
Samba | =4.3.5 | |
Samba | =4.3.6 | |
Samba | =4.4.0 | |
Ubuntu | =14.04 | |
Ubuntu | =15.10 | |
Ubuntu | =16.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-2112 has been rated as a high severity vulnerability due to its potential for man-in-the-middle attacks.
To mitigate CVE-2016-2112, upgrade your Samba installation to version 4.2.11, 4.3.8, or 4.4.2 or later.
CVE-2016-2112 affects Samba versions 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2.
CVE-2016-2112 allows attackers to perform LDAP protocol-downgrade attacks by modifying the client-server data stream.
If you cannot update, you may temporarily restrict access to LDAP services to trusted networks to reduce exposure to CVE-2016-2112.