Vulnerability Description
A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent over the wire even if Kerberos authentication was required.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Samba | Samba | >= 3.0.0, < 4.13.14 |
| Debian | Debian Linux | 9.0 |
| Fedoraproject | Fedora | 33 |
| Redhat | Codeready Linux Builder | - |
| Redhat | Gluster Storage | 3.0 |
| Redhat | Openstack | 13 |
| Redhat | Virtualization Host | 4.0 |
| Redhat | Enterprise Linux | 7.0 |
| Redhat | Enterprise Linux Desktop | 7.0 |
| Redhat | Enterprise Linux Eus | 8.2 |
| Redhat | Enterprise Linux For Ibm Z Systems | 7.0 |
| Redhat | Enterprise Linux For Ibm Z Systems Eus | 8.2 |
| Redhat | Enterprise Linux For Power Big Endian | 7.0 |
| Redhat | Enterprise Linux For Power Little Endian | 7.0 |
| Redhat | Enterprise Linux For Power Little Endian Eus | 8.2 |
| Redhat | Enterprise Linux For Scientific Computing | 7.0 |
| Redhat | Enterprise Linux Resilient Storage | 7.0 |
| Redhat | Enterprise Linux Server | 7.0 |
| Redhat | Enterprise Linux Server Aus | 8.2 |
| Redhat | Enterprise Linux Server Tus | 8.4 |
Related Weaknesses (CWE)
References
- https://bugzilla.redhat.com/show_bug.cgi?id=2019660Issue TrackingPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/09/msg00013.html
- https://security.gentoo.org/glsa/202309-06
- https://www.samba.org/samba/security/CVE-2016-2124.htmlMitigationVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2019660Issue TrackingPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/09/msg00013.html
- https://security.gentoo.org/glsa/202309-06
- https://www.samba.org/samba/security/CVE-2016-2124.htmlMitigationVendor Advisory
FAQ
What is CVE-2016-2124?
CVE-2016-2124 is a vulnerability with a CVSS score of 5.9 (MEDIUM). A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent over the wire even if Kerberos authentication was required.
How severe is CVE-2016-2124?
CVE-2016-2124 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-2124?
Check the references section above for vendor advisories and patch information. Affected products include: Samba Samba, Debian Debian Linux, Fedoraproject Fedora, Redhat Codeready Linux Builder, Redhat Gluster Storage.