8.1
CVSSv3

CVE-2018-1139

Published: 22/08/2018 Updated: 29/08/2022
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.1 | Impact Score: 5.9 | Exploitability Score: 2.2
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

A flaw was found in the way samba prior to 4.7.9 and 4.8.4 allowed the use of weak NTLMv1 authentication even when NTLMv1 was explicitly disabled. A man-in-the-middle attacker could use this flaw to read the credential and other details passed between the samba server and client.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

samba samba

redhat enterprise linux desktop 7.0

redhat enterprise linux workstation 7.0

redhat enterprise linux server 7.0

canonical ubuntu linux 16.04

canonical ubuntu linux 14.04

canonical ubuntu linux 18.04

Vendor Advisories

Several security issues were fixed in Samba ...
Synopsis Moderate: samba security, bug fix and enhancement update Type/Severity Security Advisory: Moderate Topic Updated samba packages that fix several security issues and provide several bug fixes and an enhancement are now available for Red Hat Gluster Storage 34 for Red Hat Enterprise Linux 7Red Hat ...
Synopsis Moderate: samba security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update for samba is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System ...
Synopsis Moderate: samba security, bug fix and enhancement update Type/Severity Security Advisory: Moderate Topic Updated samba packages that fix several security issues and provide several bug fixes and an enhancement are now available for Red Hat Gluster Storage 34 for Red Hat Enterprise Linux 6Red Hat ...
A null pointer dereference flaw was found in Samba RPC external printer service An attacker could use this flaw to cause the printer spooler service to crash(CVE-2018-1050) A heap-buffer overflow was found in the way samba clients processed extra long filename in a directory listing A malicious samba server could use this flaw to cause arbitrary ...
A null pointer dereference flaw was found in Samba RPC external printer service An attacker could use this flaw to cause the printer spooler service to crash (CVE-2018-1050) A heap-buffer overflow was found in the way samba clients processed extra long filename in a directory listing A malicious samba server could use this flaw to cause arbitrar ...
A flaw was found in the way samba allowed the use of weak NTLMv1 authentication even when NTLMv1 was explicitly disabled A man-in-the-middle attacker could use this flaw to read the credential and other details passed between the samba server and client ...