CVE-2018-1139
Description
A flaw was found in the way samba before 4.7.9 and 4.8.4 allowed the use of weak NTLMv1 authentication even when NTLMv1 was explicitly disabled. A man-in-the-middle attacker could use this flaw to read the credential and other details passed between the samba server and client.
Risk Information
Base Score
8.1
MODERATE
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
1.526
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| SMB/CIFS file, print, and login server for Unix (USN-3738-1) samba_4.7.6+dfsg~ubuntu-0ubuntu2.2_i386.deb | Linux |
| SMB/CIFS file, print, and login server for Unix (USN-3738-1) samba_4.7.6+dfsg~ubuntu-0ubuntu2.2_amd64.deb | Linux |
| SMB/CIFS file, print, and login server for Unix (USN-3738-1) samba_4.3.11+dfsg-0ubuntu0.14.04.16_i386.deb | Linux |
| SMB/CIFS file, print, and login server for Unix (USN-3738-1) samba_4.3.11+dfsg-0ubuntu0.14.04.16_amd64.deb | Linux |
| SMB/CIFS file, print, and login server for Unix (USN-3738-1) samba_4.3.11+dfsg-0ubuntu0.16.04.15_i386.deb | Linux |
| SMB/CIFS file, print, and login server for Unix (USN-3738-1) samba_4.3.11+dfsg-0ubuntu0.16.04.15_amd64.deb | Linux |
| Samba security update (CESA-2017:3260) ctdb-4.8.3-4.el7.x86_64.rpm | Linux |
| Samba security update (CESA-2017:3260) samba-4.8.3-4.el7.x86_64.rpm | Linux |
| Samba security update (CESA-2017:3260) samba-dc-4.8.3-4.el7.x86_64.rpm | Linux |
| Samba security update (CESA-2017:3260) ctdb-tests-4.8.3-4.el7.x86_64.rpm | Linux |
| Samba security update (CESA-2017:3260) samba-libs-4.8.3-4.el7.i686.rpm | Linux |
| Samba security update (CESA-2017:3260) samba-libs-4.8.3-4.el7.x86_64.rpm | Linux |
| Samba security update (CESA-2017:3260) samba-pidl-4.8.3-4.el7.noarch.rpm | Linux |
| Samba security update (CESA-2017:3260) samba-test-4.8.3-4.el7.x86_64.rpm | Linux |
| Samba security update (CESA-2017:3260) libwbclient-4.8.3-4.el7.i686.rpm | Linux |
| Samba security update (CESA-2017:3260) libwbclient-4.8.3-4.el7.x86_64.rpm | Linux |
| Samba security update (CESA-2017:3260) samba-devel-4.8.3-4.el7.i686.rpm | Linux |
| Samba security update (CESA-2017:3260) samba-devel-4.8.3-4.el7.x86_64.rpm | Linux |
| Samba security update (CESA-2017:3260) libsmbclient-4.8.3-4.el7.i686.rpm | Linux |
| Samba security update (CESA-2017:3260) libsmbclient-4.8.3-4.el7.x86_64.rpm | Linux |
| Samba security update (CESA-2017:3260) samba-client-4.8.3-4.el7.x86_64.rpm | Linux |
| Samba security update (CESA-2017:3260) samba-common-4.8.3-4.el7.noarch.rpm | Linux |
| Samba security update (CESA-2017:3260) samba-python-4.8.3-4.el7.x86_64.rpm | Linux |
| Samba security update (CESA-2017:3260) samba-dc-libs-4.8.3-4.el7.x86_64.rpm | Linux |
| Samba security update (CESA-2017:3260) samba-winbind-4.8.3-4.el7.x86_64.rpm | Linux |
| Samba security update (CESA-2017:3260) samba-test-libs-4.8.3-4.el7.i686.rpm | Linux |
| Samba security update (CESA-2017:3260) samba-test-libs-4.8.3-4.el7.x86_64.rpm | Linux |
| Samba security update (CESA-2017:3260) libwbclient-devel-4.8.3-4.el7.i686.rpm | Linux |
| Samba security update (CESA-2017:3260) libwbclient-devel-4.8.3-4.el7.x86_64.rpm | Linux |
| Samba security update (CESA-2017:3260) samba-client-libs-4.8.3-4.el7.i686.rpm | Linux |
| Samba security update (CESA-2017:3260) samba-client-libs-4.8.3-4.el7.x86_64.rpm | Linux |
| Samba security update (CESA-2017:3260) samba-common-libs-4.8.3-4.el7.x86_64.rpm | Linux |
| Samba security update (CESA-2017:3260) libsmbclient-devel-4.8.3-4.el7.i686.rpm | Linux |
| Samba security update (CESA-2017:3260) libsmbclient-devel-4.8.3-4.el7.x86_64.rpm | Linux |
| Samba security update (CESA-2017:3260) samba-common-tools-4.8.3-4.el7.x86_64.rpm | Linux |
| Samba security update (CESA-2017:3260) samba-krb5-printing-4.8.3-4.el7.x86_64.rpm | Linux |
| Samba security update (CESA-2017:3260) samba-vfs-glusterfs-4.8.3-4.el7.x86_64.rpm | Linux |
| Samba security update (CESA-2017:3260) samba-winbind-clients-4.8.3-4.el7.x86_64.rpm | Linux |
| Samba security update (CESA-2017:3260) samba-winbind-modules-4.8.3-4.el7.i686.rpm | Linux |
| Samba security update (CESA-2017:3260) samba-winbind-modules-4.8.3-4.el7.x86_64.rpm | Linux |
| Samba security update (CESA-2017:3260) samba-winbind-krb5-locator-4.8.3-4.el7.x86_64.rpm | Linux |
| (RHSA-2018:3056) samba security, bug fix, and enhancement update libsmbclient-4.8.3-4.el7.i686.rpm | Linux |
| (RHSA-2018:3056) samba security, bug fix, and enhancement update libsmbclient-4.8.3-4.el7.x86_64.rpm | Linux |
| (RHSA-2018:3056) samba security, bug fix, and enhancement update libsmbclient-devel-4.8.3-4.el7.i686.rpm | Linux |
| (RHSA-2018:3056) samba security, bug fix, and enhancement update libsmbclient-devel-4.8.3-4.el7.x86_64.rpm | Linux |
| (RHSA-2018:3056) samba security, bug fix, and enhancement update libwbclient-4.8.3-4.el7.i686.rpm | Linux |
| (RHSA-2018:3056) samba security, bug fix, and enhancement update libwbclient-4.8.3-4.el7.x86_64.rpm | Linux |
| (RHSA-2018:3056) samba security, bug fix, and enhancement update libwbclient-devel-4.8.3-4.el7.i686.rpm | Linux |
| (RHSA-2018:3056) samba security, bug fix, and enhancement update libwbclient-devel-4.8.3-4.el7.x86_64.rpm | Linux |
| (RHSA-2018:3056) samba security, bug fix, and enhancement update samba-4.8.3-4.el7.x86_64.rpm | Linux |
| (RHSA-2018:3056) samba security, bug fix, and enhancement update samba-client-4.8.3-4.el7.x86_64.rpm | Linux |
| (RHSA-2018:3056) samba security, bug fix, and enhancement update samba-client-libs-4.8.3-4.el7.i686.rpm | Linux |
| (RHSA-2018:3056) samba security, bug fix, and enhancement update samba-client-libs-4.8.3-4.el7.x86_64.rpm | Linux |
| (RHSA-2018:3056) samba security, bug fix, and enhancement update samba-common-4.8.3-4.el7.noarch.rpm | Linux |
| (RHSA-2018:3056) samba security, bug fix, and enhancement update samba-common-libs-4.8.3-4.el7.x86_64.rpm | Linux |
| (RHSA-2018:3056) samba security, bug fix, and enhancement update samba-common-tools-4.8.3-4.el7.x86_64.rpm | Linux |
| (RHSA-2018:3056) samba security, bug fix, and enhancement update samba-dc-4.8.3-4.el7.x86_64.rpm | Linux |
| (RHSA-2018:3056) samba security, bug fix, and enhancement update samba-dc-libs-4.8.3-4.el7.x86_64.rpm | Linux |
| (RHSA-2018:3056) samba security, bug fix, and enhancement update samba-devel-4.8.3-4.el7.i686.rpm | Linux |
| (RHSA-2018:3056) samba security, bug fix, and enhancement update samba-devel-4.8.3-4.el7.x86_64.rpm | Linux |
| (RHSA-2018:3056) samba security, bug fix, and enhancement update samba-krb5-printing-4.8.3-4.el7.x86_64.rpm | Linux |
| (RHSA-2018:3056) samba security, bug fix, and enhancement update samba-libs-4.8.3-4.el7.i686.rpm | Linux |
| (RHSA-2018:3056) samba security, bug fix, and enhancement update samba-libs-4.8.3-4.el7.x86_64.rpm | Linux |
| (RHSA-2018:3056) samba security, bug fix, and enhancement update samba-pidl-4.8.3-4.el7.noarch.rpm | Linux |
| (RHSA-2018:3056) samba security, bug fix, and enhancement update samba-python-4.8.3-4.el7.x86_64.rpm | Linux |
| (RHSA-2018:3056) samba security, bug fix, and enhancement update samba-python-test-4.8.3-4.el7.x86_64.rpm | Linux |
| (RHSA-2018:3056) samba security, bug fix, and enhancement update samba-test-4.8.3-4.el7.x86_64.rpm | Linux |
| (RHSA-2018:3056) samba security, bug fix, and enhancement update samba-test-libs-4.8.3-4.el7.i686.rpm | Linux |
| Ctdb update (ELSA-2018-3056) ctdb-4.8.3-4.el7.x86_64.rpm | Linux |
| Ctdb-tests update (ELSA-2018-3056) ctdb-tests-4.8.3-4.el7.x86_64.rpm | Linux |
| Libsmbclient update (ELSA-2018-3056) libsmbclient-4.8.3-4.el7.x86_64.rpm | Linux |
| Libsmbclient-devel update (ELSA-2018-3056) libsmbclient-devel-4.8.3-4.el7.x86_64.rpm | Linux |
| Libwbclient update (ELSA-2018-3056) libwbclient-4.8.3-4.el7.x86_64.rpm | Linux |
| Libwbclient-devel update (ELSA-2018-3056) libwbclient-devel-4.8.3-4.el7.x86_64.rpm | Linux |
| Samba update (ELSA-2018-3056) samba-4.8.3-4.el7.x86_64.rpm | Linux |
| Samba-client update (ELSA-2018-3056) samba-client-4.8.3-4.el7.x86_64.rpm | Linux |
| Samba-client-libs update (ELSA-2018-3056) samba-client-libs-4.8.3-4.el7.x86_64.rpm | Linux |
| Samba-common-libs update (ELSA-2018-3056) samba-common-libs-4.8.3-4.el7.x86_64.rpm | Linux |
| Samba-common-tools update (ELSA-2018-3056) samba-common-tools-4.8.3-4.el7.x86_64.rpm | Linux |
| Samba-dc update (ELSA-2018-3056) samba-dc-4.8.3-4.el7.x86_64.rpm | Linux |
| Samba-dc-libs update (ELSA-2018-3056) samba-dc-libs-4.8.3-4.el7.x86_64.rpm | Linux |
| Samba-devel update (ELSA-2018-3056) samba-devel-4.8.3-4.el7.x86_64.rpm | Linux |
| Samba-krb5-printing update (ELSA-2018-3056) samba-krb5-printing-4.8.3-4.el7.x86_64.rpm | Linux |
| Samba-libs update (ELSA-2018-3056) samba-libs-4.8.3-4.el7.x86_64.rpm | Linux |
| Samba-python update (ELSA-2018-3056) samba-python-4.8.3-4.el7.x86_64.rpm | Linux |
| Samba-python-test update (ELSA-2018-3056) samba-python-test-4.8.3-4.el7.x86_64.rpm | Linux |
| Samba-test update (ELSA-2018-3056) samba-test-4.8.3-4.el7.x86_64.rpm | Linux |
| Samba-test-libs update (ELSA-2018-3056) samba-test-libs-4.8.3-4.el7.x86_64.rpm | Linux |
| Samba-vfs-glusterfs update (ELSA-2018-3056) samba-vfs-glusterfs-4.8.3-4.el7.x86_64.rpm | Linux |
| Samba-winbind update (ELSA-2018-3056) samba-winbind-4.8.3-4.el7.x86_64.rpm | Linux |
| Samba-winbind-clients update (ELSA-2018-3056) samba-winbind-clients-4.8.3-4.el7.x86_64.rpm | Linux |
| Samba-winbind-krb5-locator update (ELSA-2018-3056) samba-winbind-krb5-locator-4.8.3-4.el7.x86_64.rpm | Linux |
| Samba-winbind-modules update (ELSA-2018-3056) samba-winbind-modules-4.8.3-4.el7.x86_64.rpm | Linux |
| Samba-common update (ELSA-2018-3056) samba-common-4.8.3-4.el7.noarch.rpm | Linux |
| Samba-pidl update (ELSA-2018-3056) samba-pidl-4.8.3-4.el7.noarch.rpm | Linux |
| Libsmbclient update (ELSA-2018-3056) libsmbclient-4.8.3-4.el7.i686.rpm | Linux |
| Libsmbclient-devel update (ELSA-2018-3056) libsmbclient-devel-4.8.3-4.el7.i686.rpm | Linux |
| Libwbclient update (ELSA-2018-3056) libwbclient-4.8.3-4.el7.i686.rpm | Linux |
| Libwbclient-devel update (ELSA-2018-3056) libwbclient-devel-4.8.3-4.el7.i686.rpm | Linux |
| Samba-client-libs update (ELSA-2018-3056) samba-client-libs-4.8.3-4.el7.i686.rpm | Linux |
| Samba-devel update (ELSA-2018-3056) samba-devel-4.8.3-4.el7.i686.rpm | Linux |
| Samba-libs update (ELSA-2018-3056) samba-libs-4.8.3-4.el7.i686.rpm | Linux |
| Samba-test-libs update (ELSA-2018-3056) samba-test-libs-4.8.3-4.el7.i686.rpm | Linux |
| Samba-winbind-modules update (ELSA-2018-3056) samba-winbind-modules-4.8.3-4.el7.i686.rpm | Linux |
| Insufficiently Protected Credentials Vulnerability (CVE-2018-1139) | NCM |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234