Lucene search

K
f5F5F5:K37603172
HistoryMay 10, 2016 - 12:00 a.m.

K37603172 : Samba vulnerabilities CVE-2015-5370 and CVE-2016-2118

2016-05-1000:00:00
my.f5.com
40

7.7 High

AI Score

Confidence

High

0.028 Low

EPSS

Percentile

90.7%

Security Advisory Description

Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not properly implement the DCE-RPC layer, which allows remote attackers to perform protocol-downgrade attacks, cause a denial of service (application crash or CPU consumption), or possibly execute arbitrary code on a client system via unspecified vectors.

The MS-SAMR and MS-LSAD protocol implementations in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 mishandle DCERPC connections, which allows man-in-the-middle attackers to perform protocol-downgrade attacks and impersonate users by modifying the client-server data stream, aka “BADLOCK.”
Impact
This vulnerability may allow a remote attacker to perform protocol-downgrade attacks, cause a denial of service (application crash or CPU consumption), or execute arbitrary code on a client system.