The Samba Active Directory LDAP server was vulnerable to an information disclosure flaw because of missing access control checks. An authenticated attacker could use this flaw to extract confidential attribute values using LDAP search expressions. Samba versions before 4.6.16, 4.7.9 and 4.8.4 are vulnerable.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-4271-1 | samba security update |
EUVD |
EUVD-2018-2973 | The Samba Active Directory LDAP server was vulnerable to an information disclosure flaw because of missing access control checks. An authenticated attacker could use this flaw to extract confidential attribute values using LDAP search expressions. Samba versions before 4.6.16, 4.7.9 and 4.8.4 are vulnerable. |
Ubuntu USN |
USN-3738-1 | Samba vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-05T07:54:36.241Z
Reserved: 2018-05-09T00:00:00
Link: CVE-2018-10919
No data.
Status : Modified
Published: 2018-08-22T17:29:00.603
Modified: 2024-11-21T03:42:18.223
Link: CVE-2018-10919
OpenCVE Enrichment
No data.
Debian DSA
EUVD
Ubuntu USN