CVE-2018-1139
published 2018-08-22CVE-2018-1139: A flaw was found in the way samba before 4.7.9 and 4.8.4 allowed the use of weak NTLMv1 authentication even when NTLMv1 was explicitly disabled. A…
PriorityP343high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
3.10%
86.4th percentile
A flaw was found in the way samba before 4.7.9 and 4.8.4 allowed the use of weak NTLMv1 authentication even when NTLMv1 was explicitly disabled. A man-in-the-middle attacker could use this flaw to read the credential and other details passed between the samba server and client.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | samba | < samba 2:4.8.4+dfsg-1 (bookworm) | samba 2:4.8.4+dfsg-1 (bookworm) |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| samba | samba | >= 0 < 2:4.8.4+dfsg-1 | 2:4.8.4+dfsg-1 |
| samba | samba | >= 0 < 2:4.8.4+dfsg-1 | 2:4.8.4+dfsg-1 |
| samba | samba | >= 0 < 2:4.8.4+dfsg-1 | 2:4.8.4+dfsg-1 |
| samba | samba | >= 0 < 2:4.8.4+dfsg-1 | 2:4.8.4+dfsg-1 |
| samba | samba | >= 0 < 2:4.3.11+dfsg-0ubuntu0.14.04.16 | 2:4.3.11+dfsg-0ubuntu0.14.04.16 |
| samba | samba | >= 0 < 2:4.3.11+dfsg-0ubuntu0.16.04.15 | 2:4.3.11+dfsg-0ubuntu0.16.04.15 |
| samba | samba | >= 0 < 2:4.7.6+dfsg~ubuntu-0ubuntu2.2 | 2:4.7.6+dfsg~ubuntu-0ubuntu2.2 |
| samba | samba | >= 4.7.0 < 4.7.9 | 4.7.9 |
| samba | samba | >= 4.8.0 < 4.8.4 | 4.8.4 |
| the_samba_team | samba | — | — |
| the_samba_team | samba | — | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.05.4MEDIUMCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv8.8HIGH
vendor_debian8.1HIGH
vendor_redhat8.1HIGH
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
samba: Weak authentication protocol regression
vendor_redhat·2018-08-16·CVSS 8.1
CVE-2018-1139 [HIGH] CWE-20 samba: Weak authentication protocol regression
samba: Weak authentication protocol regression
A flaw was found in the way samba before 4.7.9 and 4.8.4 allowed the use of weak NTLMv1 authentication even when NTLMv1 was explicitly disabled. A man-in-the-middle attacker could use this flaw to read the credential and other details passed between the samba server and client.
A flaw was found in the way samba allowed the use of weak NTLMv1 authentication even when NTLMv1 was explicitly disabled. A man-in-the-middle attacker could use this flaw to read the credential and other details passed between the samba server and client.
Package: samba (Red Hat Enterprise Linux 5) - Not affected
Package: samba3x (Red Hat Enterprise Linux 5) - Not affected
Package: samba (Red Hat Enterprise Linux 6) - Not affected
Package: samba4 (Red Hat Enterpri
Ubuntu
Samba vulnerabilities
vendor_ubuntu·2018-08-14·CVSS 4.3
CVE-2018-10858 [MEDIUM] Samba vulnerabilities
Title: Samba vulnerabilities
Summary: Several security issues were fixed in Samba.
Svyatoslav Phirsov discovered that the Samba libsmbclient library
incorrectly handled extra long filenames. A malicious server could use this
issue to cause Samba to crash, resulting in a denial of service, or
possibly execute arbitrary code. (CVE-2018-10858)
Volker Mauel discovered that Samba incorrectly handled database output.
When used as an Active Directory Domain Controller, a remote authenticated
attacker could use this issue to cause Samba to crash, resulting in a
denial of service. This issue only affected Ubuntu 18.04 LTS.
(CVE-2018-10918)
Phillip Kuhrt discovered that the Samba LDAP server incorrectly handled
certain confidential attribute values. A remote authenticated attacker
could possibly
Debian
CVE-2018-1139: samba - A flaw was found in the way samba before 4.7.9 and 4.8.4 allowed the use of weak...
vendor_debian·2018·CVSS 8.1
CVE-2018-1139 [HIGH] CVE-2018-1139: samba - A flaw was found in the way samba before 4.7.9 and 4.8.4 allowed the use of weak...
A flaw was found in the way samba before 4.7.9 and 4.8.4 allowed the use of weak NTLMv1 authentication even when NTLMv1 was explicitly disabled. A man-in-the-middle attacker could use this flaw to read the credential and other details passed between the samba server and client.
Scope: local
bookworm: resolved (fixed in 2:4.8.4+dfsg-1)
bullseye: resolved (fixed in 2:4.8.4+dfsg-1)
forky: resolved (fixed in 2:4.8.4+dfsg-1)
sid: resolved (fixed in 2:4.8.4+dfsg-1)
trixie: resolved (fixed in 2:4.8.4+dfsg-1)
GHSA
GHSA-xxm3-fp55-pm48: A flaw was found in the way samba before 4
ghsa_unreviewed·2022-05-13
CVE-2018-1139 [HIGH] CWE-522 GHSA-xxm3-fp55-pm48: A flaw was found in the way samba before 4
A flaw was found in the way samba before 4.7.9 and 4.8.4 allowed the use of weak NTLMv1 authentication even when NTLMv1 was explicitly disabled. A man-in-the-middle attacker could use this flaw to read the credential and other details passed between the samba server and client.
OSV
CVE-2018-1139: A flaw was found in the way samba before 4
osv·2018-08-22·CVSS 8.1
CVE-2018-1139 [HIGH] CVE-2018-1139: A flaw was found in the way samba before 4
A flaw was found in the way samba before 4.7.9 and 4.8.4 allowed the use of weak NTLMv1 authentication even when NTLMv1 was explicitly disabled. A man-in-the-middle attacker could use this flaw to read the credential and other details passed between the samba server and client.
OSV
samba vulnerabilities
osv·2018-08-14·CVSS 8.8
CVE-2018-10858 [HIGH] samba vulnerabilities
samba vulnerabilities
Svyatoslav Phirsov discovered that the Samba libsmbclient library
incorrectly handled extra long filenames. A malicious server could use this
issue to cause Samba to crash, resulting in a denial of service, or
possibly execute arbitrary code. (CVE-2018-10858)
Volker Mauel discovered that Samba incorrectly handled database output.
When used as an Active Directory Domain Controller, a remote authenticated
attacker could use this issue to cause Samba to crash, resulting in a
denial of service. This issue only affected Ubuntu 18.04 LTS.
(CVE-2018-10918)
Phillip Kuhrt discovered that the Samba LDAP server incorrectly handled
certain confidential attribute values. A remote authenticated attacker
could possibly use this issue to obtain certain sensitive information.
(CVE-
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-1139 samba: Weak authentication protocol regression [fedora-all]
bugzilla·2018-08-16·CVSS 8.1
CVE-2018-1139 [HIGH] CVE-2018-1139 samba: Weak authentication protocol regression [fedora-all]
CVE-2018-1139 samba: Weak authentication protocol regression [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of
Bugzilla
CVE-2018-1139 samba: Weak authentication protocol regression
bugzilla·2018-06-11·CVSS 8.1
CVE-2018-1139 [HIGH] CVE-2018-1139 samba: Weak authentication protocol regression
CVE-2018-1139 samba: Weak authentication protocol regression
As per upstream advisory:
Samba releases 4.7.0 to 4.8.0 (inclusive) contain an error which allows authentication using NTLMv1 over an SMB1 transport, even when NTLMv1 is explicitly disabled. This problem does not occur over SMB2, it is a SMB1-only issue.
Normally, the use of NTLMv1 is disabled by default in favor of NTLMv2. This has been the default since Samba 4.5. A code restructuring in the NTLM authentication implementation of Samba in 4.7.0 caused this regression to occur.
Discussion:
Acknowledgments:
Name: Vivek Das (Red Hat)
---
External Reference:
https://www.samba.org/samba/security/CVE-2018-1139.html
---
Created samba tracking bugs for this issue:
Affects: fedora-all [bug 1617916]
---
This issue has been a
arXiv
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
arxiv_fulltext·2022-12-29
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
## Abstract
Currently, the development of IoT firmware heavily depends on third-party components (TPCs) to improve development efficiency. Nevertheless, TPCs are not secure, and the vulnerabilities in TPCs will influence the security of IoT firmware. Existing works pay less attention to the vulnerabilities caused by TPCs, and we still lack a comprehensive understanding of the security impact of TPC vulnerability against firmware. To fill in the knowledge gap, we design and implement , which leverages syntactical features and control-flow graph features to detect the TPCs in firmware, and then recognizes the corresponding vulnerabilities. Based on , we present the first l
http://www.securityfocus.com/bid/105084https://access.redhat.com/errata/RHSA-2018:2612https://access.redhat.com/errata/RHSA-2018:2613https://access.redhat.com/errata/RHSA-2018:3056https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1139https://security.gentoo.org/glsa/202003-52https://security.netapp.com/advisory/ntap-20180814-0001/https://usn.ubuntu.com/3738-1/https://www.samba.org/samba/security/CVE-2018-1139.htmlhttp://www.securityfocus.com/bid/105084https://access.redhat.com/errata/RHSA-2018:2612https://access.redhat.com/errata/RHSA-2018:2613https://access.redhat.com/errata/RHSA-2018:3056https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1139https://security.gentoo.org/glsa/202003-52https://security.netapp.com/advisory/ntap-20180814-0001/https://usn.ubuntu.com/3738-1/https://www.samba.org/samba/security/CVE-2018-1139.html
2018-08-22
Published