SB2018081448 - Weakn encryption in samba (Alpine package)
Published: August 14, 2018
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Weakn encryption (CVE-ID: CVE-2018-1139)
The vulnerability allows a remote attacker to bypass certain security restrictions.
The vulnerability exists due to an error that allows usage of NTLMv1 encryption protocol over SMB1 transport, even when NTLMv1 is explicitly disabled.
Remediation
Install update from vendor's website.