Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-1139

Опубликовано: 16 авг. 2018
Источник: redhat
CVSS3: 5.4

Описание

A flaw was found in the way samba before 4.7.9 and 4.8.4 allowed the use of weak NTLMv1 authentication even when NTLMv1 was explicitly disabled. A man-in-the-middle attacker could use this flaw to read the credential and other details passed between the samba server and client.

A flaw was found in the way samba allowed the use of weak NTLMv1 authentication even when NTLMv1 was explicitly disabled. A man-in-the-middle attacker could use this flaw to read the credential and other details passed between the samba server and client.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5sambaNot affected
Red Hat Enterprise Linux 5samba3xNot affected
Red Hat Enterprise Linux 6sambaNot affected
Red Hat Enterprise Linux 6samba4Not affected
Red Hat Enterprise Linux 8sambaNot affected
Red Hat Enterprise Linux 7sambaFixedRHSA-2018:305630.10.2018
Red Hat Gluster Storage 3.4 for RHEL 6libtallocFixedRHSA-2018:261204.09.2018
Red Hat Gluster Storage 3.4 for RHEL 6libtdbFixedRHSA-2018:261204.09.2018
Red Hat Gluster Storage 3.4 for RHEL 6libteventFixedRHSA-2018:261204.09.2018
Red Hat Gluster Storage 3.4 for RHEL 6sambaFixedRHSA-2018:261204.09.2018

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1589651samba: Weak authentication protocol regression

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
почти 7 лет назад

A flaw was found in the way samba before 4.7.9 and 4.8.4 allowed the use of weak NTLMv1 authentication even when NTLMv1 was explicitly disabled. A man-in-the-middle attacker could use this flaw to read the credential and other details passed between the samba server and client.

CVSS3: 8.1
nvd
почти 7 лет назад

A flaw was found in the way samba before 4.7.9 and 4.8.4 allowed the use of weak NTLMv1 authentication even when NTLMv1 was explicitly disabled. A man-in-the-middle attacker could use this flaw to read the credential and other details passed between the samba server and client.

CVSS3: 8.1
debian
почти 7 лет назад

A flaw was found in the way samba before 4.7.9 and 4.8.4 allowed the u ...

CVSS3: 8.1
github
около 3 лет назад

A flaw was found in the way samba before 4.7.9 and 4.8.4 allowed the use of weak NTLMv1 authentication even when NTLMv1 was explicitly disabled. A man-in-the-middle attacker could use this flaw to read the credential and other details passed between the samba server and client.

CVSS3: 8.1
fstec
почти 7 лет назад

Уязвимость компонента аутентификации NTLMv1 программ сетевого взаимодействия Samba, позволяющая нарушителю получить несанкционированный доступ к конфиденциальным данным

5.4 Medium

CVSS3