CVE-2018-1139

A flaw was found in the way samba before 4.7.9 and 4.8.4 allowed the use of weak NTLMv1 authentication even when NTLMv1 was explicitly disabled. A man-in-the-middle attacker could use this flaw to read the credential and other details passed between the samba server and client.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*

History

29 Aug 2022, 20:43

Type Values Removed Values Added
CPE cpe:2.3:a:samba:samba:4.8.4:*:*:*:*:*:*:*
References (GENTOO) https://security.gentoo.org/glsa/202003-52 - (GENTOO) https://security.gentoo.org/glsa/202003-52 - Third Party Advisory

Information

Published : 2018-08-22 14:29

Updated : 2023-12-10 12:44


NVD link : CVE-2018-1139

Mitre link : CVE-2018-1139

CVE.ORG link : CVE-2018-1139


JSON object : View

Products Affected

redhat

  • enterprise_linux_server
  • enterprise_linux_desktop
  • enterprise_linux_workstation

canonical

  • ubuntu_linux

samba

  • samba
CWE
CWE-522

Insufficiently Protected Credentials

CWE-20

Improper Input Validation