Vulnerability Description
A flaw was found in the way samba client before samba 4.4.16, samba 4.5.14 and samba 4.6.8 used encryption with the max protocol set as SMB3. The connection could lose the requirement for signing and encrypting to any DFS redirects, allowing an attacker to read or alter the contents of the connection via a man-in-the-middle attack.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Samba | Samba | < 4.4.16 |
| Debian | Debian Linux | 8.0 |
| Redhat | Enterprise Linux | 7.0 |
| Redhat | Enterprise Linux Desktop | 7.0 |
| Redhat | Enterprise Linux Server Aus | 7.4 |
| Redhat | Enterprise Linux Server Eus | 7.4 |
| Redhat | Enterprise Linux Workstation | 7.0 |
| Hp | Cifs Server | b.04.05.11.00 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/100917Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1039401Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2017:2790Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2858Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-12151Issue TrackingThird Party Advisory
- https://security.netapp.com/advisory/ntap-20170921-0001/Third Party Advisory
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpeThird Party Advisory
- https://www.debian.org/security/2017/dsa-3983Third Party Advisory
- https://www.samba.org/samba/security/CVE-2017-12151.htmlMitigationVendor Advisory
- http://www.securityfocus.com/bid/100917Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1039401Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2017:2790Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2858Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-12151Issue TrackingThird Party Advisory
- https://security.netapp.com/advisory/ntap-20170921-0001/Third Party Advisory
FAQ
What is CVE-2017-12151?
CVE-2017-12151 is a vulnerability with a CVSS score of 7.4 (HIGH). A flaw was found in the way samba client before samba 4.4.16, samba 4.5.14 and samba 4.6.8 used encryption with the max protocol set as SMB3. The connection could lose the requirement for signing and ...
How severe is CVE-2017-12151?
CVE-2017-12151 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-12151?
Check the references section above for vendor advisories and patch information. Affected products include: Samba Samba, Debian Debian Linux, Redhat Enterprise Linux, Redhat Enterprise Linux Desktop, Redhat Enterprise Linux Server Aus.