CVE-2018-10919
Last modified
CVE-2018-10919 is a vulnerability of currently unknown severity. The Samba Active Directory LDAP server was vulnerable to an information disclosure flaw because of missing access control checks. An authenticated attacker could use this flaw to extract confidential attribute values using LDAP search expressions. EPSS estimates a 2.20% chance of exploitation in the next 30 days.
Description
The Samba Active Directory LDAP server was vulnerable to an information disclosure flaw because of missing access control checks. An authenticated attacker could use this flaw to extract confidential attribute values using LDAP search expressions. Samba versions before 4.6.16, 4.7.9 and 4.8.4 are vulnerable.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Canonical | Ubuntu Linux | 14.04 |
| Canonical | Ubuntu Linux | 16.04 |
| Canonical | Ubuntu Linux | 18.04 |
| Debian | Debian Linux | 9.0 |
| Samba | Samba | >= 4.0.0, < 4.6.16 |
| Samba | Samba | >= 4.7.0, < 4.7.9 |
| Samba | Samba | >= 4.8.0, < 4.8.4 |
References
- http://www.securityfocus.com/bid/105081Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10919Issue Tracking, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20180814-0001/Third Party Advisory
- https://usn.ubuntu.com/3738-1/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4271Third Party Advisory
- https://www.samba.org/samba/security/CVE-2018-10919.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/105081Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10919Issue Tracking, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20180814-0001/Third Party Advisory
- https://usn.ubuntu.com/3738-1/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4271Third Party Advisory
- https://www.samba.org/samba/security/CVE-2018-10919.htmlPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-10919?
How severe is CVE-2018-10919?
How do I fix CVE-2018-10919?
Are you affected by CVE-2018-10919?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
