Red Hat fixes the Badlock vulnerability in Samba.

Source: Internet
Author: User
Tags cve gluster

Red Hat fixes the Badlock vulnerability in Samba.

Red Hat recently announced the Protocol defects in its product interaction with Windows AD and Samba service, this vulnerability affects Red Hat Identity Management, Red Hat Gluster Storage, and RHEL Samba servers and clients.

Red Hat Access Labs has built specialized Vulnerability Detection and Analysis rules to help users understand the risks caused by their published vulnerabilities. We recommend that you install patches as soon as possible.

Vulnerability details

Badlock is a "Protocol/man-in-the-middle" attack vulnerability that can be exploited by simulating a user identity verified by Windows AD. In this attack, attackers can be granted permissions to read and write the SAM Database, which may cause leakage of all user names and passwords and other sensitive information.

Badlock vulnerabilities have been marked as CVE-2016-2118 by Red Hat security team, security level is important, the administrator can visit the Red Hat official website to obtain information and repair as soon as possible.

Note: This Samba protocol issue is described in Red Hat using a CVE-2016-2118, which is described in Microsoft's Security Bulletin using a CVE-2016-0128, although the two CVE IDs are different, but it is about Badlock.

This vulnerability may affect the following applications:

  • File servers or print servers that affect the Samba Service
  • Red Hat Identity Management product using Samba
  • Users who have installed Samba in Red Hat Gluster Storage
  • Using Samba as an AD Domain Member Server is vulnerable to this vulnerability. Attackers can impersonate a client to obtain authentication communications between domain members and domain controllers.

This article permanently updates the link address:

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.