ISOMAN

CVE

CVE-2016-2112

The bundled LDAP client library in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not recognize the "client ldap sasl wrapping" setting, which allows man-in-the-middle attackers to perform LDAP protocol-downgrade attacks by modifying the client-server data stream.

Severity
MEDIUM
CVSS
5.9
Published
Modified

Linked Releases

References

  1. http://badlock.org/
  2. http://lists.fedoraproject.org/pipermail/package-announce/2016-April/182185.html
  3. http://lists.fedoraproject.org/pipermail/package-announce/2016-April/182272.html
  4. http://lists.fedoraproject.org/pipermail/package-announce/2016-April/182288.html
  5. http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00020.html
  6. http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00021.html
  7. http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00022.html
  8. http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00023.html
  9. http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00024.html
  10. http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00042.html
  11. http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00047.html
  12. http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00048.html
  13. http://rhn.redhat.com/errata/RHSA-2016-0611.html
  14. http://rhn.redhat.com/errata/RHSA-2016-0612.html
  15. http://rhn.redhat.com/errata/RHSA-2016-0613.html
  16. http://rhn.redhat.com/errata/RHSA-2016-0614.html
  17. http://rhn.redhat.com/errata/RHSA-2016-0618.html
  18. http://rhn.redhat.com/errata/RHSA-2016-0619.html
  19. http://rhn.redhat.com/errata/RHSA-2016-0620.html
  20. http://rhn.redhat.com/errata/RHSA-2016-0624.html