Bug 1589651 (CVE-2018-1139) - CVE-2018-1139 samba: Weak authentication protocol regression
Summary: CVE-2018-1139 samba: Weak authentication protocol regression
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2018-1139
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1614265 1614744 1617915 1617916
Blocks: 1577167
TreeView+ depends on / blocked
 
Reported: 2018-06-11 05:38 UTC by Huzaifa S. Sidhpurwala
Modified: 2022-03-13 15:05 UTC (History)
16 users (show)

Fixed In Version: samba 4.7.9, samba 4.8.4
Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in the way samba allowed the use of weak NTLMv1 authentication even when NTLMv1 was explicitly disabled. A man-in-the-middle attacker could use this flaw to read the credential and other details passed between the samba server and client.
Clone Of:
Environment:
Last Closed: 2019-06-10 10:28:36 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2018:2612 0 None None None 2018-09-04 06:31:55 UTC
Red Hat Product Errata RHSA-2018:2613 0 None None None 2018-09-04 06:29:30 UTC
Red Hat Product Errata RHSA-2018:3056 0 None None None 2018-10-30 07:26:32 UTC

Description Huzaifa S. Sidhpurwala 2018-06-11 05:38:10 UTC
As per upstream advisory:

Samba releases 4.7.0 to 4.8.0 (inclusive) contain an error which allows authentication using NTLMv1 over an SMB1 transport, even when NTLMv1 is explicitly disabled. This problem does not occur over SMB2, it is a SMB1-only issue.

Normally, the use of NTLMv1 is disabled by default in favor of NTLMv2. This has been the default since Samba 4.5. A code restructuring in the NTLM authentication implementation of Samba in 4.7.0 caused this regression to occur.

Comment 2 Huzaifa S. Sidhpurwala 2018-06-11 05:45:40 UTC
Acknowledgments:

Name: Vivek Das (Red Hat)

Comment 4 Sam Fowler 2018-08-16 03:32:02 UTC
External Reference:

https://www.samba.org/samba/security/CVE-2018-1139.html

Comment 5 Sam Fowler 2018-08-16 07:14:30 UTC
Created samba tracking bugs for this issue:

Affects: fedora-all [bug 1617916]

Comment 7 errata-xmlrpc 2018-09-04 06:29:23 UTC
This issue has been addressed in the following products:

  Red Hat Gluster Storage 3.4 for RHEL 7

Via RHSA-2018:2613 https://access.redhat.com/errata/RHSA-2018:2613

Comment 8 errata-xmlrpc 2018-09-04 06:31:46 UTC
This issue has been addressed in the following products:

  Red Hat Gluster Storage 3.4 for RHEL 6

Via RHSA-2018:2612 https://access.redhat.com/errata/RHSA-2018:2612

Comment 9 errata-xmlrpc 2018-10-30 07:26:24 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2018:3056 https://access.redhat.com/errata/RHSA-2018:3056


Note You need to log in before you can comment on or make changes to this bug.