CVE-2018-10919
Summary
| CVE | CVE-2018-10919 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-08-22 17:29:00 UTC |
| Updated | 2019-10-09 23:33:00 UTC |
| Description | The Samba Active Directory LDAP server was vulnerable to an information disclosure flaw because of missing access control checks. An authenticated attacker could use this flaw to extract confidential attribute values using LDAP search expressions. Samba versions before 4.6.16, 4.7.9 and 4.8.4 are vulnerable. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| USN-3738-1: Samba vulnerabilities | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| 1610645 – (CVE-2018-10919) CVE-2018-10919 samba: Confidential attribute disclosure via substring search |
CONFIRM |
bugzilla.redhat.com |
Issue Tracking, Third Party Advisory |
| August 2018 Samba Vulnerabilities in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
Third Party Advisory |
| Debian -- Security Information -- DSA-4271-1 samba |
DEBIAN |
www.debian.org |
Third Party Advisory |
| Samba - Security Announcement Archive |
CONFIRM |
www.samba.org |
Patch, Vendor Advisory |
| Samba CVE-2018-10919 Access Bypass Vulnerability |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| Samba: Multiple vulnerabilities (GLSA 202003-52) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 500636 Alpine Linux Security Update for samba
- 504400 Alpine Linux Security Update for samba
- 671121 EulerOS Security Update for samba (EulerOS-SA-2019-2484)