ALPINE-CVE-2018-1139 PUBLISHED CVSS 8.100000381469727 HIGH

A flaw was found in the way samba before 4.7.9 and 4.8.4 allowed the use of weak NTLMv1 authentication even when NTLMv1 was explicitly disabled. A man-in-the-middle attacker could use this flaw to read the credential and other details passed between the samba server and client.

Risk Scores

CVSS v3.1
8.100000381469727
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Alpine:v3.21samba4.8.2-r1, 0, 3.2.10-r0
Alpine:v3.15samba0, 4.8.2-r1, 4.8.2-r0
Alpine:v3.19samba0, 4.8.2-r1, 4.8.2-r0
Alpine:v3.8samba4.8.2-r1, 0, 3.2.11-r0
Alpine:v3.18samba0, 3.2.10-r0, 3.2.11-r0
Alpine:v3.22samba4.8.2-r1, 4.8.2-r0, 4.8.1-r0
Alpine:v3.10samba3.2.11-r0, 3.2.10-r0, 4.8.2-r1
Alpine:v3.16samba0, 3.2.10-r0, 3.2.11-r0
Alpine:v3.14samba4.7.0-r1, 0, 3.2.11-r0
Alpine:v3.17samba0, 3.2.10-r0, 3.2.11-r0
Alpine:v3.20samba0, 3.2.11-r0, 3.2.11-r1
Alpine:v3.23samba4.7.3-r0, 3.2.10-r0, 3.2.11-r0
Alpine:v3.11samba4.8.2-r1, 4.8.2-r0, 4.8.1-r0
Alpine:v3.12samba3.5.6-r0, 4.8.2-r1, 4.8.2-r0
Alpine:v3.13samba4.1.10-r0, 4.8.2-r1, 4.8.2-r0
Alpine:v3.9samba4.8.2-r1, 4.1.1-r0, 4.1.10-r0
Alpine:v3.7samba4.7.6-r0, 4.7.4-r0, 4.7.3-r0

Timeline

References

Open in Interactive Console →