CVE-2018-1139: Input Validation
A flaw was found in the way samba before 4.7.9 and 4.8.4 allowed the use of weak NTLMv1 authentication even when NTLMv1 was explicitly disabled. A man-in-the-middle attacker could use this flaw to read the credential and other details passed between the samba server and client.
Other sources
As per upstream advisory:
Samba releases 4.7.0 to 4.8.0 (inclusive) contain an error which allows authentication using NTLMv1 over an SMB1 transport, even when NTLMv1 is explicitly disabled. This problem does not occur over SMB2, it is a SMB1-only issue.
Normally, the use of NTLMv1 is disabled by default in favor of NTLMv2. This has been the default since Samba 4.5. A code restructuring in the NTLM authentication implementation of Samba in 4.7.0 caused this regression to occur.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-1139?
CVE-2018-1139 is a vulnerability in Samba that allows the use of weak NTLMv1 authentication.
What is the severity of CVE-2018-1139?
CVE-2018-1139 has a severity rating of 8.1 (high).
How does CVE-2018-1139 affect Samba?
CVE-2018-1139 affects Samba versions before 4.7.9 and 4.8.4.
How can a man-in-the-middle attacker exploit CVE-2018-1139?
A man-in-the-middle attacker can exploit CVE-2018-1139 to read the credential and other details passed between the Samba server and client.
Where can I find more information about CVE-2018-1139?
You can find more information about CVE-2018-1139 on the Samba website, the RedHat Bugzilla page, and the RedHat errata page.