Upstream information

CVE-2016-2114 at MITRE

Description

The SMB1 protocol implementation in Samba 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not recognize the "server signing = mandatory" setting, which allows man-in-the-middle attackers to spoof SMB servers by modifying the client-server data stream.

SUSE information

CVSS v2 Scores
  National Vulnerability Database SUSE
Base Score 4.30 5.76
Vector AV:N/AC:M/Au:N/C:N/I:P/A:N AV:N/AC:M/Au:N/C:P/I:P/A:N
Access Vector Network Network
Access Complexity Medium Medium
Authentication None None
Confidentiality Impact None Partial
Integrity Impact Partial Partial
Availability Impact None None
CVSS v3 Scores
  National Vulnerability Database
Base Score 5.9
Vector AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Access Vector Network
Access Complexity High
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality Impact None
Integrity Impact High
Availability Impact None

Note from the SUSE Security Team

We have not shipped the affected component so far, so SUSE has not been affected by this problem.

SUSE Bugzilla entry: 973035 [RESOLVED / FIXED]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
openSUSE 13.1
  • ctdb >= 4.2.4-3.54.2
  • ctdb-debuginfo >= 4.2.4-3.54.2
  • ctdb-devel >= 4.2.4-3.54.2
  • ctdb-pcp-pmda >= 4.2.4-3.54.2
  • ctdb-pcp-pmda-debuginfo >= 4.2.4-3.54.2
  • ctdb-tests >= 4.2.4-3.54.2
  • ctdb-tests-debuginfo >= 4.2.4-3.54.2
  • libdcerpc-atsvc-devel >= 4.2.4-3.54.2
  • libdcerpc-atsvc0 >= 4.2.4-3.54.2
  • libdcerpc-atsvc0-32bit >= 4.2.4-3.54.2
  • libdcerpc-atsvc0-debuginfo >= 4.2.4-3.54.2
  • libdcerpc-atsvc0-debuginfo-32bit >= 4.2.4-3.54.2
  • libdcerpc-binding0 >= 4.2.4-3.54.2
  • libdcerpc-binding0-32bit >= 4.2.4-3.54.2
  • libdcerpc-binding0-debuginfo >= 4.2.4-3.54.2
  • libdcerpc-binding0-debuginfo-32bit >= 4.2.4-3.54.2
  • libdcerpc-devel >= 4.2.4-3.54.2
  • libdcerpc-samr-devel >= 4.2.4-3.54.2
  • libdcerpc-samr0 >= 4.2.4-3.54.2
  • libdcerpc-samr0-32bit >= 4.2.4-3.54.2
  • libdcerpc-samr0-debuginfo >= 4.2.4-3.54.2
  • libdcerpc-samr0-debuginfo-32bit >= 4.2.4-3.54.2
  • libdcerpc0 >= 4.2.4-3.54.2
  • libdcerpc0-32bit >= 4.2.4-3.54.2
  • libdcerpc0-debuginfo >= 4.2.4-3.54.2
  • libdcerpc0-debuginfo-32bit >= 4.2.4-3.54.2
  • libgensec-devel >= 4.2.4-3.54.2
  • libgensec0 >= 4.2.4-3.54.2
  • libgensec0-32bit >= 4.2.4-3.54.2
  • libgensec0-debuginfo >= 4.2.4-3.54.2
  • libgensec0-debuginfo-32bit >= 4.2.4-3.54.2
  • libndr-devel >= 4.2.4-3.54.2
  • libndr-krb5pac-devel >= 4.2.4-3.54.2
  • libndr-krb5pac0 >= 4.2.4-3.54.2
  • libndr-krb5pac0-32bit >= 4.2.4-3.54.2
  • libndr-krb5pac0-debuginfo >= 4.2.4-3.54.2
  • libndr-krb5pac0-debuginfo-32bit >= 4.2.4-3.54.2
  • libndr-nbt-devel >= 4.2.4-3.54.2
  • libndr-nbt0 >= 4.2.4-3.54.2
  • libndr-nbt0-32bit >= 4.2.4-3.54.2
  • libndr-nbt0-debuginfo >= 4.2.4-3.54.2
  • libndr-nbt0-debuginfo-32bit >= 4.2.4-3.54.2
  • libndr-standard-devel >= 4.2.4-3.54.2
  • libndr-standard0 >= 4.2.4-3.54.2
  • libndr-standard0-32bit >= 4.2.4-3.54.2
  • libndr-standard0-debuginfo >= 4.2.4-3.54.2
  • libndr-standard0-debuginfo-32bit >= 4.2.4-3.54.2
  • libndr0 >= 4.2.4-3.54.2
  • libndr0-32bit >= 4.2.4-3.54.2
  • libndr0-debuginfo >= 4.2.4-3.54.2
  • libndr0-debuginfo-32bit >= 4.2.4-3.54.2
  • libnetapi-devel >= 4.2.4-3.54.2
  • libnetapi0 >= 4.2.4-3.54.2
  • libnetapi0-32bit >= 4.2.4-3.54.2
  • libnetapi0-debuginfo >= 4.2.4-3.54.2
  • libnetapi0-debuginfo-32bit >= 4.2.4-3.54.2
  • libregistry-devel >= 4.2.4-3.54.2
  • libregistry0 >= 4.2.4-3.54.2
  • libregistry0-32bit >= 4.2.4-3.54.2
  • libregistry0-debuginfo >= 4.2.4-3.54.2
  • libregistry0-debuginfo-32bit >= 4.2.4-3.54.2
  • libsamba-credentials-devel >= 4.2.4-3.54.2
  • libsamba-credentials0 >= 4.2.4-3.54.2
  • libsamba-credentials0-32bit >= 4.2.4-3.54.2
  • libsamba-credentials0-debuginfo >= 4.2.4-3.54.2
  • libsamba-credentials0-debuginfo-32bit >= 4.2.4-3.54.2
  • libsamba-hostconfig-devel >= 4.2.4-3.54.2
  • libsamba-hostconfig0 >= 4.2.4-3.54.2
  • libsamba-hostconfig0-32bit >= 4.2.4-3.54.2
  • libsamba-hostconfig0-debuginfo >= 4.2.4-3.54.2
  • libsamba-hostconfig0-debuginfo-32bit >= 4.2.4-3.54.2
  • libsamba-passdb-devel >= 4.2.4-3.54.2
  • libsamba-passdb0 >= 4.2.4-3.54.2
  • libsamba-passdb0-32bit >= 4.2.4-3.54.2
  • libsamba-passdb0-debuginfo >= 4.2.4-3.54.2
  • libsamba-passdb0-debuginfo-32bit >= 4.2.4-3.54.2
  • libsamba-policy-devel >= 4.2.4-3.54.2
  • libsamba-policy0 >= 4.2.4-3.54.2
  • libsamba-policy0-32bit >= 4.2.4-3.54.2
  • libsamba-policy0-debuginfo >= 4.2.4-3.54.2
  • libsamba-policy0-debuginfo-32bit >= 4.2.4-3.54.2
  • libsamba-util-devel >= 4.2.4-3.54.2
  • libsamba-util0 >= 4.2.4-3.54.2
  • libsamba-util0-32bit >= 4.2.4-3.54.2
  • libsamba-util0-debuginfo >= 4.2.4-3.54.2
  • libsamba-util0-debuginfo-32bit >= 4.2.4-3.54.2
  • libsamdb-devel >= 4.2.4-3.54.2
  • libsamdb0 >= 4.2.4-3.54.2
  • libsamdb0-32bit >= 4.2.4-3.54.2
  • libsamdb0-debuginfo >= 4.2.4-3.54.2
  • libsamdb0-debuginfo-32bit >= 4.2.4-3.54.2
  • libsmbclient-devel >= 4.2.4-3.54.2
  • libsmbclient-raw-devel >= 4.2.4-3.54.2
  • libsmbclient-raw0 >= 4.2.4-3.54.2
  • libsmbclient-raw0-32bit >= 4.2.4-3.54.2
  • libsmbclient-raw0-debuginfo >= 4.2.4-3.54.2
  • libsmbclient-raw0-debuginfo-32bit >= 4.2.4-3.54.2
  • libsmbclient0 >= 4.2.4-3.54.2
  • libsmbclient0-32bit >= 4.2.4-3.54.2
  • libsmbclient0-debuginfo >= 4.2.4-3.54.2
  • libsmbclient0-debuginfo-32bit >= 4.2.4-3.54.2
  • libsmbconf-devel >= 4.2.4-3.54.2
  • libsmbconf0 >= 4.2.4-3.54.2
  • libsmbconf0-32bit >= 4.2.4-3.54.2
  • libsmbconf0-debuginfo >= 4.2.4-3.54.2
  • libsmbconf0-debuginfo-32bit >= 4.2.4-3.54.2
  • libsmbldap-devel >= 4.2.4-3.54.2
  • libsmbldap0 >= 4.2.4-3.54.2
  • libsmbldap0-32bit >= 4.2.4-3.54.2
  • libsmbldap0-debuginfo >= 4.2.4-3.54.2
  • libsmbldap0-debuginfo-32bit >= 4.2.4-3.54.2
  • libtevent-util-devel >= 4.2.4-3.54.2
  • libtevent-util0 >= 4.2.4-3.54.2
  • libtevent-util0-32bit >= 4.2.4-3.54.2
  • libtevent-util0-debuginfo >= 4.2.4-3.54.2
  • libtevent-util0-debuginfo-32bit >= 4.2.4-3.54.2
  • libwbclient-devel >= 4.2.4-3.54.2
  • libwbclient0 >= 4.2.4-3.54.2
  • libwbclient0-32bit >= 4.2.4-3.54.2
  • libwbclient0-debuginfo >= 4.2.4-3.54.2
  • libwbclient0-debuginfo-32bit >= 4.2.4-3.54.2
  • samba >= 4.2.4-3.54.2
  • samba-32bit >= 4.2.4-3.54.2
  • samba-client >= 4.2.4-3.54.2
  • samba-client-32bit >= 4.2.4-3.54.2
  • samba-client-debuginfo >= 4.2.4-3.54.2
  • samba-client-debuginfo-32bit >= 4.2.4-3.54.2
  • samba-core-devel >= 4.2.4-3.54.2
  • samba-debuginfo >= 4.2.4-3.54.2
  • samba-debuginfo-32bit >= 4.2.4-3.54.2
  • samba-debugsource >= 4.2.4-3.54.2
  • samba-doc >= 4.2.4-3.54.2
  • samba-libs >= 4.2.4-3.54.2
  • samba-libs-32bit >= 4.2.4-3.54.2
  • samba-libs-debuginfo >= 4.2.4-3.54.2
  • samba-libs-debuginfo-32bit >= 4.2.4-3.54.2
  • samba-pidl >= 4.2.4-3.54.2
  • samba-python >= 4.2.4-3.54.2
  • samba-python-debuginfo >= 4.2.4-3.54.2
  • samba-test >= 4.2.4-3.54.2
  • samba-test-debuginfo >= 4.2.4-3.54.2
  • samba-test-devel >= 4.2.4-3.54.2
  • samba-winbind >= 4.2.4-3.54.2
  • samba-winbind-32bit >= 4.2.4-3.54.2
  • samba-winbind-debuginfo >= 4.2.4-3.54.2
  • samba-winbind-debuginfo-32bit >= 4.2.4-3.54.2
Patchnames:
2016-490
openSUSE Evergreen 11.4
  • ctdb >= 4.2.4-3.54.2
  • ctdb-debuginfo >= 4.2.4-3.54.2
  • ctdb-devel >= 4.2.4-3.54.2
  • ctdb-pcp-pmda >= 4.2.4-3.54.2
  • ctdb-pcp-pmda-debuginfo >= 4.2.4-3.54.2
  • ctdb-tests >= 4.2.4-3.54.2
  • ctdb-tests-debuginfo >= 4.2.4-3.54.2
  • ldapsmb >= 1.34b-141.1
  • libdcerpc-atsvc-devel >= 4.2.4-3.54.2
  • libdcerpc-atsvc0 >= 4.2.4-3.54.2
  • libdcerpc-atsvc0-32bit >= 4.2.4-3.54.2
  • libdcerpc-atsvc0-debuginfo >= 4.2.4-3.54.2
  • libdcerpc-atsvc0-debuginfo-32bit >= 4.2.4-3.54.2
  • libdcerpc-binding0 >= 4.2.4-3.54.2
  • libdcerpc-binding0-32bit >= 4.2.4-3.54.2
  • libdcerpc-binding0-debuginfo >= 4.2.4-3.54.2
  • libdcerpc-binding0-debuginfo-32bit >= 4.2.4-3.54.2
  • libdcerpc-devel >= 4.2.4-3.54.2
  • libdcerpc-samr-devel >= 4.2.4-3.54.2
  • libdcerpc-samr0 >= 4.2.4-3.54.2
  • libdcerpc-samr0-32bit >= 4.2.4-3.54.2
  • libdcerpc-samr0-debuginfo >= 4.2.4-3.54.2
  • libdcerpc-samr0-debuginfo-32bit >= 4.2.4-3.54.2
  • libdcerpc0 >= 4.2.4-3.54.2
  • libdcerpc0-32bit >= 4.2.4-3.54.2
  • libdcerpc0-debuginfo >= 4.2.4-3.54.2
  • libdcerpc0-debuginfo-32bit >= 4.2.4-3.54.2
  • libgensec-devel >= 4.2.4-3.54.2
  • libgensec0 >= 4.2.4-3.54.2
  • libgensec0-32bit >= 4.2.4-3.54.2
  • libgensec0-debuginfo >= 4.2.4-3.54.2
  • libgensec0-debuginfo-32bit >= 4.2.4-3.54.2
  • libldb-devel >= 1.0.2-141.1
  • libldb1 >= 1.0.2-141.1
  • libldb1-32bit >= 1.0.2-141.1
  • libldb1-debuginfo >= 1.0.2-141.1
  • libldb1-debuginfo-32bit >= 1.0.2-141.1
  • libldb1-debuginfo-x86 >= 1.0.2-141.1
  • libldb1-x86 >= 1.0.2-141.1
  • libndr-devel >= 4.2.4-3.54.2
  • libndr-krb5pac-devel >= 4.2.4-3.54.2
  • libndr-krb5pac0 >= 4.2.4-3.54.2
  • libndr-krb5pac0-32bit >= 4.2.4-3.54.2
  • libndr-krb5pac0-debuginfo >= 4.2.4-3.54.2
  • libndr-krb5pac0-debuginfo-32bit >= 4.2.4-3.54.2
  • libndr-nbt-devel >= 4.2.4-3.54.2
  • libndr-nbt0 >= 4.2.4-3.54.2
  • libndr-nbt0-32bit >= 4.2.4-3.54.2
  • libndr-nbt0-debuginfo >= 4.2.4-3.54.2
  • libndr-nbt0-debuginfo-32bit >= 4.2.4-3.54.2
  • libndr-standard-devel >= 4.2.4-3.54.2
  • libndr-standard0 >= 4.2.4-3.54.2
  • libndr-standard0-32bit >= 4.2.4-3.54.2
  • libndr-standard0-debuginfo >= 4.2.4-3.54.2
  • libndr-standard0-debuginfo-32bit >= 4.2.4-3.54.2
  • libndr0 >= 4.2.4-3.54.2
  • libndr0-32bit >= 4.2.4-3.54.2
  • libndr0-debuginfo >= 4.2.4-3.54.2
  • libndr0-debuginfo-32bit >= 4.2.4-3.54.2
  • libnetapi-devel >= 3.6.3-141.1
  • libnetapi0 >= 3.6.3-141.1
  • libnetapi0-32bit >= 4.2.4-3.54.2
  • libnetapi0-debuginfo >= 3.6.3-141.1
  • libnetapi0-debuginfo-32bit >= 4.2.4-3.54.2
  • libregistry-devel >= 4.2.4-3.54.2
  • libregistry0 >= 4.2.4-3.54.2
  • libregistry0-32bit >= 4.2.4-3.54.2
  • libregistry0-debuginfo >= 4.2.4-3.54.2
  • libregistry0-debuginfo-32bit >= 4.2.4-3.54.2
  • libsamba-credentials-devel >= 4.2.4-3.54.2
  • libsamba-credentials0 >= 4.2.4-3.54.2
  • libsamba-credentials0-32bit >= 4.2.4-3.54.2
  • libsamba-credentials0-debuginfo >= 4.2.4-3.54.2
  • libsamba-credentials0-debuginfo-32bit >= 4.2.4-3.54.2
  • libsamba-hostconfig-devel >= 4.2.4-3.54.2
  • libsamba-hostconfig0 >= 4.2.4-3.54.2
  • libsamba-hostconfig0-32bit >= 4.2.4-3.54.2
  • libsamba-hostconfig0-debuginfo >= 4.2.4-3.54.2
  • libsamba-hostconfig0-debuginfo-32bit >= 4.2.4-3.54.2
  • libsamba-passdb-devel >= 4.2.4-3.54.2
  • libsamba-passdb0 >= 4.2.4-3.54.2
  • libsamba-passdb0-32bit >= 4.2.4-3.54.2
  • libsamba-passdb0-debuginfo >= 4.2.4-3.54.2
  • libsamba-passdb0-debuginfo-32bit >= 4.2.4-3.54.2
  • libsamba-policy-devel >= 4.2.4-3.54.2
  • libsamba-policy0 >= 4.2.4-3.54.2
  • libsamba-policy0-32bit >= 4.2.4-3.54.2
  • libsamba-policy0-debuginfo >= 4.2.4-3.54.2
  • libsamba-policy0-debuginfo-32bit >= 4.2.4-3.54.2
  • libsamba-util-devel >= 4.2.4-3.54.2
  • libsamba-util0 >= 4.2.4-3.54.2
  • libsamba-util0-32bit >= 4.2.4-3.54.2
  • libsamba-util0-debuginfo >= 4.2.4-3.54.2
  • libsamba-util0-debuginfo-32bit >= 4.2.4-3.54.2
  • libsamdb-devel >= 4.2.4-3.54.2
  • libsamdb0 >= 4.2.4-3.54.2
  • libsamdb0-32bit >= 4.2.4-3.54.2
  • libsamdb0-debuginfo >= 4.2.4-3.54.2
  • libsamdb0-debuginfo-32bit >= 4.2.4-3.54.2
  • libsmbclient-devel >= 3.6.3-141.1
  • libsmbclient-raw-devel >= 4.2.4-3.54.2
  • libsmbclient-raw0 >= 4.2.4-3.54.2
  • libsmbclient-raw0-32bit >= 4.2.4-3.54.2
  • libsmbclient-raw0-debuginfo >= 4.2.4-3.54.2
  • libsmbclient-raw0-debuginfo-32bit >= 4.2.4-3.54.2
  • libsmbclient0 >= 3.6.3-141.1
  • libsmbclient0-32bit >= 3.6.3-141.1
  • libsmbclient0-debuginfo >= 3.6.3-141.1
  • libsmbclient0-debuginfo-32bit >= 3.6.3-141.1
  • libsmbclient0-debuginfo-x86 >= 3.6.3-141.1
  • libsmbclient0-x86 >= 3.6.3-141.1
  • libsmbconf-devel >= 4.2.4-3.54.2
  • libsmbconf0 >= 4.2.4-3.54.2
  • libsmbconf0-32bit >= 4.2.4-3.54.2
  • libsmbconf0-debuginfo >= 4.2.4-3.54.2
  • libsmbconf0-debuginfo-32bit >= 4.2.4-3.54.2
  • libsmbldap-devel >= 4.2.4-3.54.2
  • libsmbldap0 >= 4.2.4-3.54.2
  • libsmbldap0-32bit >= 4.2.4-3.54.2
  • libsmbldap0-debuginfo >= 4.2.4-3.54.2
  • libsmbldap0-debuginfo-32bit >= 4.2.4-3.54.2
  • libsmbsharemodes-devel >= 3.6.3-141.1
  • libsmbsharemodes0 >= 3.6.3-141.1
  • libsmbsharemodes0-debuginfo >= 3.6.3-141.1
  • libtalloc-devel >= 2.0.5-141.1
  • libtalloc2 >= 2.0.5-141.1
  • libtalloc2-32bit >= 2.0.5-141.1
  • libtalloc2-debuginfo >= 2.0.5-141.1
  • libtalloc2-debuginfo-32bit >= 2.0.5-141.1
  • libtalloc2-debuginfo-x86 >= 2.0.5-141.1
  • libtalloc2-x86 >= 2.0.5-141.1
  • libtdb-devel >= 1.2.9-141.1
  • libtdb1 >= 1.2.9-141.1
  • libtdb1-32bit >= 1.2.9-141.1
  • libtdb1-debuginfo >= 1.2.9-141.1
  • libtdb1-debuginfo-32bit >= 1.2.9-141.1
  • libtdb1-debuginfo-x86 >= 1.2.9-141.1
  • libtdb1-x86 >= 1.2.9-141.1
  • libtevent-devel >= 0.9.11-141.1
  • libtevent-util-devel >= 4.2.4-3.54.2
  • libtevent-util0 >= 4.2.4-3.54.2
  • libtevent-util0-32bit >= 4.2.4-3.54.2
  • libtevent-util0-debuginfo >= 4.2.4-3.54.2
  • libtevent-util0-debuginfo-32bit >= 4.2.4-3.54.2
  • libtevent0 >= 0.9.11-141.1
  • libtevent0-32bit >= 0.9.11-141.1
  • libtevent0-debuginfo >= 0.9.11-141.1
  • libtevent0-debuginfo-32bit >= 0.9.11-141.1
  • libtevent0-debuginfo-x86 >= 0.9.11-141.1
  • libtevent0-x86 >= 0.9.11-141.1
  • libwbclient-devel >= 3.6.3-141.1
  • libwbclient0 >= 3.6.3-141.1
  • libwbclient0-32bit >= 3.6.3-141.1
  • libwbclient0-debuginfo >= 3.6.3-141.1
  • libwbclient0-debuginfo-32bit >= 3.6.3-141.1
  • libwbclient0-debuginfo-x86 >= 3.6.3-141.1
  • libwbclient0-x86 >= 3.6.3-141.1
  • samba >= 3.6.3-141.1
  • samba-32bit >= 3.6.3-141.1
  • samba-client >= 3.6.3-141.1
  • samba-client-32bit >= 3.6.3-141.1
  • samba-client-debuginfo >= 3.6.3-141.1
  • samba-client-debuginfo-32bit >= 3.6.3-141.1
  • samba-client-debuginfo-x86 >= 3.6.3-141.1
  • samba-client-x86 >= 3.6.3-141.1
  • samba-core-devel >= 4.2.4-3.54.2
  • samba-debuginfo >= 3.6.3-141.1
  • samba-debuginfo-32bit >= 3.6.3-141.1
  • samba-debuginfo-x86 >= 3.6.3-141.1
  • samba-debugsource >= 3.6.3-141.1
  • samba-devel >= 3.6.3-141.1
  • samba-doc >= 3.6.3-141.1
  • samba-krb-printing >= 3.6.3-141.1
  • samba-krb-printing-debuginfo >= 3.6.3-141.1
  • samba-libs >= 4.2.4-3.54.2
  • samba-libs-32bit >= 4.2.4-3.54.2
  • samba-libs-debuginfo >= 4.2.4-3.54.2
  • samba-libs-debuginfo-32bit >= 4.2.4-3.54.2
  • samba-pidl >= 4.2.4-3.54.2
  • samba-python >= 4.2.4-3.54.2
  • samba-python-debuginfo >= 4.2.4-3.54.2
  • samba-test >= 4.2.4-3.54.2
  • samba-test-debuginfo >= 4.2.4-3.54.2
  • samba-test-devel >= 4.2.4-3.54.2
  • samba-winbind >= 3.6.3-141.1
  • samba-winbind-32bit >= 3.6.3-141.1
  • samba-winbind-debuginfo >= 3.6.3-141.1
  • samba-winbind-debuginfo-32bit >= 3.6.3-141.1
  • samba-winbind-debuginfo-x86 >= 3.6.3-141.1
  • samba-winbind-x86 >= 3.6.3-141.1
  • samba-x86 >= 3.6.3-141.1
Patchnames:
2016-490