The NTLMSSP authentication implementation in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 allows man-in-the-middle attackers to perform protocol-downgrade attacks by modifying the client-server data stream to remove application-layer flags or encryption settings, as demonstrated by clearing the NTLMSSPNEGOTIATESEAL or NTLMSSPNEGOTIATESIGN option to disrupt LDAP security.
{ "availability": "No subscription required", "binaries": [ { "binary_name": "libnss-winbind", "binary_version": "2:4.3.8+dfsg-0ubuntu0.14.04.2" }, { "binary_name": "libpam-smbpass", "binary_version": "2:4.3.8+dfsg-0ubuntu0.14.04.2" }, { "binary_name": "libpam-winbind", "binary_version": "2:4.3.8+dfsg-0ubuntu0.14.04.2" }, { "binary_name": "libparse-pidl-perl", "binary_version": "2:4.3.8+dfsg-0ubuntu0.14.04.2" }, { "binary_name": "libsmbclient", "binary_version": "2:4.3.8+dfsg-0ubuntu0.14.04.2" }, { "binary_name": "libsmbclient-dev", "binary_version": "2:4.3.8+dfsg-0ubuntu0.14.04.2" }, { "binary_name": "libsmbsharemodes-dev", "binary_version": "2:4.3.8+dfsg-0ubuntu0.14.04.2" }, { "binary_name": "libsmbsharemodes0", "binary_version": "2:4.3.8+dfsg-0ubuntu0.14.04.2" }, { "binary_name": "libwbclient-dev", "binary_version": "2:4.3.8+dfsg-0ubuntu0.14.04.2" }, { "binary_name": "libwbclient0", "binary_version": "2:4.3.8+dfsg-0ubuntu0.14.04.2" }, { "binary_name": "python-samba", "binary_version": "2:4.3.8+dfsg-0ubuntu0.14.04.2" }, { "binary_name": "registry-tools", "binary_version": "2:4.3.8+dfsg-0ubuntu0.14.04.2" }, { "binary_name": "samba", "binary_version": "2:4.3.8+dfsg-0ubuntu0.14.04.2" }, { "binary_name": "samba-common", "binary_version": "2:4.3.8+dfsg-0ubuntu0.14.04.2" }, { "binary_name": "samba-common-bin", "binary_version": "2:4.3.8+dfsg-0ubuntu0.14.04.2" }, { "binary_name": "samba-dev", "binary_version": "2:4.3.8+dfsg-0ubuntu0.14.04.2" }, { "binary_name": "samba-dsdb-modules", "binary_version": "2:4.3.8+dfsg-0ubuntu0.14.04.2" }, { "binary_name": "samba-libs", "binary_version": "2:4.3.8+dfsg-0ubuntu0.14.04.2" }, { "binary_name": "samba-testsuite", "binary_version": "2:4.3.8+dfsg-0ubuntu0.14.04.2" }, { "binary_name": "samba-vfs-modules", "binary_version": "2:4.3.8+dfsg-0ubuntu0.14.04.2" }, { "binary_name": "smbclient", "binary_version": "2:4.3.8+dfsg-0ubuntu0.14.04.2" }, { "binary_name": "winbind", "binary_version": "2:4.3.8+dfsg-0ubuntu0.14.04.2" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_name": "ctdb", "binary_version": "2:4.3.8+dfsg-0ubuntu1" }, { "binary_name": "libnss-winbind", "binary_version": "2:4.3.8+dfsg-0ubuntu1" }, { "binary_name": "libpam-winbind", "binary_version": "2:4.3.8+dfsg-0ubuntu1" }, { "binary_name": "libparse-pidl-perl", "binary_version": "2:4.3.8+dfsg-0ubuntu1" }, { "binary_name": "libsmbclient", "binary_version": "2:4.3.8+dfsg-0ubuntu1" }, { "binary_name": "libsmbclient-dev", "binary_version": "2:4.3.8+dfsg-0ubuntu1" }, { "binary_name": "libwbclient-dev", "binary_version": "2:4.3.8+dfsg-0ubuntu1" }, { "binary_name": "libwbclient0", "binary_version": "2:4.3.8+dfsg-0ubuntu1" }, { "binary_name": "python-samba", "binary_version": "2:4.3.8+dfsg-0ubuntu1" }, { "binary_name": "registry-tools", "binary_version": "2:4.3.8+dfsg-0ubuntu1" }, { "binary_name": "samba", "binary_version": "2:4.3.8+dfsg-0ubuntu1" }, { "binary_name": "samba-common", "binary_version": "2:4.3.8+dfsg-0ubuntu1" }, { "binary_name": "samba-common-bin", "binary_version": "2:4.3.8+dfsg-0ubuntu1" }, { "binary_name": "samba-dev", "binary_version": "2:4.3.8+dfsg-0ubuntu1" }, { "binary_name": "samba-dsdb-modules", "binary_version": "2:4.3.8+dfsg-0ubuntu1" }, { "binary_name": "samba-libs", "binary_version": "2:4.3.8+dfsg-0ubuntu1" }, { "binary_name": "samba-testsuite", "binary_version": "2:4.3.8+dfsg-0ubuntu1" }, { "binary_name": "samba-vfs-modules", "binary_version": "2:4.3.8+dfsg-0ubuntu1" }, { "binary_name": "smbclient", "binary_version": "2:4.3.8+dfsg-0ubuntu1" }, { "binary_name": "winbind", "binary_version": "2:4.3.8+dfsg-0ubuntu1" } ] }