Description
The Samba Active Directory LDAP server was vulnerable to an information disclosure flaw because of missing access control checks. An authenticated attacker could use this flaw to extract confidential attribute values using LDAP search expressions. Samba versions before 4.6.16, 4.7.9 and 4.8.4 are vulnerable.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-4271-1 | samba security update |
EUVD |
EUVD-2018-2973 | The Samba Active Directory LDAP server was vulnerable to an information disclosure flaw because of missing access control checks. An authenticated attacker could use this flaw to extract confidential attribute values using LDAP search expressions. Samba versions before 4.6.16, 4.7.9 and 4.8.4 are vulnerable. |
Ubuntu USN |
USN-3738-1 | Samba vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-05T07:54:36.241Z
Reserved: 2018-05-09T00:00:00.000Z
Link: CVE-2018-10919
No data.
Status : Modified
Published: 2018-08-22T17:29:00.603
Modified: 2024-11-21T03:42:18.223
Link: CVE-2018-10919
OpenCVE Enrichment
No data.
Debian DSA
EUVD
Ubuntu USN