ISOMAN

CVE

CVE-2018-1139

A flaw was found in the way samba before 4.7.9 and 4.8.4 allowed the use of weak NTLMv1 authentication even when NTLMv1 was explicitly disabled. A man-in-the-middle attacker could use this flaw to read the credential and other details passed between the samba server and client.

Severity
HIGH
CVSS
8.1
Published
Modified

Linked Releases

References

  1. http://www.securityfocus.com/bid/105084
  2. https://access.redhat.com/errata/RHSA-2018:2612
  3. https://access.redhat.com/errata/RHSA-2018:2613
  4. https://access.redhat.com/errata/RHSA-2018:3056
  5. https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1139
  6. https://security.gentoo.org/glsa/202003-52
  7. https://security.netapp.com/advisory/ntap-20180814-0001/
  8. https://usn.ubuntu.com/3738-1/
  9. https://www.samba.org/samba/security/CVE-2018-1139.html
  10. http://www.securityfocus.com/bid/105084
  11. https://access.redhat.com/errata/RHSA-2018:2612
  12. https://access.redhat.com/errata/RHSA-2018:2613
  13. https://access.redhat.com/errata/RHSA-2018:3056
  14. https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1139
  15. https://security.gentoo.org/glsa/202003-52
  16. https://security.netapp.com/advisory/ntap-20180814-0001/
  17. https://usn.ubuntu.com/3738-1/
  18. https://www.samba.org/samba/security/CVE-2018-1139.html