SB2018081448 - Weakn encryption in samba (Alpine package)



SB2018081448 - Weakn encryption in samba (Alpine package)

Published: August 14, 2018

Security Bulletin ID SB2018081448
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Adjecent network
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Weakn encryption (CVE-ID: CVE-2018-1139)

The vulnerability allows a remote attacker to bypass certain security restrictions.

The vulnerability exists due to an error that allows usage of NTLMv1 encryption protocol over SMB1 transport, even when NTLMv1 is explicitly disabled.


Remediation

Install update from vendor's website.