High severity7.4NVD Advisory· Published Apr 25, 2016· Updated May 6, 2026
CVE-2016-2113
CVE-2016-2113
Description
Samba 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not verify X.509 certificates from TLS servers, which allows man-in-the-middle attackers to spoof LDAPS and HTTPS servers and obtain sensitive information via a crafted certificate.
Affected products
75cpe:2.3:a:samba:samba:4.0.0:*:*:*:*:*:*:*+ 71 more
- cpe:2.3:a:samba:samba:4.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.0.10:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.0.11:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.0.12:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.0.13:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.0.14:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.0.15:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.0.16:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.0.17:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.0.18:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.0.19:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.0.20:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.0.21:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.0.22:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.0.23:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.0.24:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.0.25:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.0.26:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.0.5:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.0.6:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.0.7:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.0.8:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.0.9:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.1.10:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.1.11:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.1.12:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.1.13:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.1.14:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.1.15:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.1.16:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.1.17:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.1.18:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.1.19:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.1.20:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.1.21:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.1.22:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.1.23:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.1.3:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.1.4:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.1.5:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.1.6:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.1.7:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.1.8:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.1.9:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.2.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.2.0:rc2:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.2.0:rc3:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.2.0:rc4:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.2.3:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.2.4:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.2.5:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.2.6:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.2.7:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.2.8:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.2.9:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.3.1:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.3.2:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.3.3:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.3.4:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.3.5:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.3.6:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.4.0:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*+ 2 more
- cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
30- www.samba.org/samba/security/CVE-2016-2113.htmlnvdPatchVendor Advisory
- badlock.orgnvd
- lists.fedoraproject.org/pipermail/package-announce/2016-April/182185.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2016-April/182272.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2016-April/182288.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2016-04/msg00020.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2016-04/msg00021.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2016-04/msg00022.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2016-04/msg00023.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2016-04/msg00024.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2016-04/msg00042.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2016-04/msg00047.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2016-04/msg00048.htmlnvd
- rhn.redhat.com/errata/RHSA-2016-0612.htmlnvd
- rhn.redhat.com/errata/RHSA-2016-0614.htmlnvd
- rhn.redhat.com/errata/RHSA-2016-0618.htmlnvd
- rhn.redhat.com/errata/RHSA-2016-0620.htmlnvd
- www.debian.org/security/2016/dsa-3548nvd
- www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlnvd
- www.securitytracker.com/id/1035533nvd
- www.slackware.com/security/viewer.phpnvd
- www.ubuntu.com/usn/USN-2950-1nvd
- www.ubuntu.com/usn/USN-2950-2nvd
- www.ubuntu.com/usn/USN-2950-3nvd
- www.ubuntu.com/usn/USN-2950-4nvd
- www.ubuntu.com/usn/USN-2950-5nvd
- bto.bluecoat.com/security-advisory/sa122nvd
- security.gentoo.org/glsa/201612-47nvd
- www.samba.org/samba/history/samba-4.2.10.htmlnvd
- www.samba.org/samba/latest_news.htmlnvd
News mentions
0No linked articles in our index yet.