CVE
CVE-2018-10919
The Samba Active Directory LDAP server was vulnerable to an information disclosure flaw because of missing access control checks. An authenticated attacker could use this flaw to extract confidential attribute values using LDAP search expressions. Samba versions before 4.6.16, 4.7.9 and 4.8.4 are vulnerable.
- Severity
- MEDIUM
- CVSS
- 4.3
- Published
- Modified
Linked Releases
| Distribution | Release | Status | Evidence |
|---|---|---|---|
| Ubuntu | 18.04.6 amd64 desktop | unknown | source |
| Ubuntu | 18.04.6 amd64 live-server | unknown | source |
| Ubuntu | 16.04.7 amd64 desktop | unknown | source |
| Ubuntu | 16.04.6 i386 desktop | unknown | source |
| Ubuntu | 16.04.7 amd64 server | unknown | source |
| Ubuntu | 16.04.6 i386 server | unknown | source |
| Ubuntu | 14.04.6 amd64 desktop | unknown | source |
| Ubuntu | 14.04.6 i386 desktop | unknown | source |
| Ubuntu | 14.04.6 amd64 server | unknown | source |
| Ubuntu | 14.04.6 i386 server | unknown | source |
References
- http://www.securityfocus.com/bid/105081
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10919
- https://security.gentoo.org/glsa/202003-52
- https://security.netapp.com/advisory/ntap-20180814-0001/
- https://usn.ubuntu.com/3738-1/
- https://www.debian.org/security/2018/dsa-4271
- https://www.samba.org/samba/security/CVE-2018-10919.html
- http://www.securityfocus.com/bid/105081
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10919
- https://security.gentoo.org/glsa/202003-52
- https://security.netapp.com/advisory/ntap-20180814-0001/
- https://usn.ubuntu.com/3738-1/
- https://www.debian.org/security/2018/dsa-4271
- https://www.samba.org/samba/security/CVE-2018-10919.html