A flaw was found in the way samba client before samba 4.4.16, samba 4.5.14 and samba 4.6.8 used encryption with the max protocol set as SMB3. The connection could lose the requirement for signing and encrypting to any DFS redirects, allowing an attacker to read or alter the contents of the connection via a man-in-the-middle attack.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2018-07-27T12:00:00

Updated: 2024-08-05T18:28:16.367Z

Reserved: 2017-08-01T00:00:00

Link: CVE-2017-12151

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-07-27T12:29:00.223

Modified: 2024-11-21T03:08:56.363

Link: CVE-2017-12151

cve-icon Redhat

Severity : Moderate

Publid Date: 2017-09-20T00:00:00Z

Links: CVE-2017-12151 - Bugzilla