CVE-2018-1139

A flaw was found in the way samba before 4.7.9 and 4.8.4 allowed the use of weak NTLMv1 authentication even when NTLMv1 was explicitly disabled. A man-in-the-middle attacker could use this flaw to read the credential and other details passed between the samba server and client.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.1 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 82%
Affected Products (NVD)
VendorProductVersion
sambasamba
4.7.0 ≤
𝑥
< 4.7.9
sambasamba
4.8.0 ≤
𝑥
< 4.8.4
canonicalubuntu_linux
14.04
canonicalubuntu_linux
16.04
canonicalubuntu_linux
18.04
redhatenterprise_linux_desktop
7.0
redhatenterprise_linux_server
7.0
redhatenterprise_linux_workstation
7.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
samba
bookworm
2:4.17.12+dfsg-0+deb12u1
fixed
bookworm (security)
2:4.17.12+dfsg-0+deb12u1
fixed
bullseye
2:4.13.13+dfsg-1~deb11u6
fixed
bullseye (security)
2:4.13.13+dfsg-1~deb11u6
fixed
jessie
not-affected
sid
2:4.21.1+dfsg-2
fixed
stretch
not-affected
trixie
2:4.21.1+dfsg-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
samba
bionic
Fixed 2:4.7.6+dfsg~ubuntu-0ubuntu2.2
released
trusty
not-affected
xenial
not-affected
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
ctdb
RHEL 7
0:4.8.3-4.el7
fixed
ctdb-tests
RHEL 7
0:4.8.3-4.el7
fixed
libsmbclient
RHEL 7
0:4.8.3-4.el7
fixed
libsmbclient-devel
RHEL 7
0:4.8.3-4.el7
fixed
libwbclient
RHEL 7
0:4.8.3-4.el7
fixed
libwbclient-devel
RHEL 7
0:4.8.3-4.el7
fixed
samba
RHEL 7
0:4.8.3-4.el7
fixed
samba-client
RHEL 7
0:4.8.3-4.el7
fixed
samba-client-libs
RHEL 7
0:4.8.3-4.el7
fixed
samba-common
RHEL 7
0:4.8.3-4.el7
fixed
samba-common-libs
RHEL 7
0:4.8.3-4.el7
fixed
samba-common-tools
RHEL 7
0:4.8.3-4.el7
fixed
samba-dc
RHEL 7
0:4.8.3-4.el7
fixed
samba-dc-libs
RHEL 7
0:4.8.3-4.el7
fixed
samba-devel
RHEL 7
0:4.8.3-4.el7
fixed
samba-krb5-printing
RHEL 7
0:4.8.3-4.el7
fixed
samba-libs
RHEL 7
0:4.8.3-4.el7
fixed
samba-pidl
RHEL 7
0:4.8.3-4.el7
fixed
samba-python
RHEL 7
0:4.8.3-4.el7
fixed
samba-python-test
RHEL 7
0:4.8.3-4.el7
fixed
samba-test
RHEL 7
0:4.8.3-4.el7
fixed
samba-test-libs
RHEL 7
0:4.8.3-4.el7
fixed
samba-vfs-glusterfs
RHEL 7
0:4.8.3-4.el7
fixed
samba-winbind
RHEL 7
0:4.8.3-4.el7
fixed
samba-winbind-clients
RHEL 7
0:4.8.3-4.el7
fixed
samba-winbind-krb5-locator
RHEL 7
0:4.8.3-4.el7
fixed
samba-winbind-modules
RHEL 7
0:4.8.3-4.el7
fixed