VulnerabilityModified
CVE-2018-10919
The Samba Active Directory LDAP server was vulnerable to an information disclosure flaw because of missing access control checks.
MEDIUM 6.5EPSS 2.18%
Does this matter?
Lower severity and a low EPSS score (2.18%). Track it; it rarely justifies an emergency change on its own.
Description
The Samba Active Directory LDAP server was vulnerable to an information disclosure flaw because of missing access control checks. An authenticated attacker could use this flaw to extract confidential attribute values using LDAP search expressions. Samba versions before 4.6.16, 4.7.9 and 4.8.4 are vulnerable.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 2.18% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-203, CWE-200
- Affected
- canonical/ubuntu linux · debian/debian linux · samba/samba
- Source
- secalert@redhat.com
References
- http://www.securityfocus.com/bid/105081Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10919Issue Tracking, Third Party Advisory
- https://security.gentoo.org/glsa/202003-52
- https://security.netapp.com/advisory/ntap-20180814-0001/Third Party Advisory
- https://usn.ubuntu.com/3738-1/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4271Third Party Advisory
- https://www.samba.org/samba/security/CVE-2018-10919.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/105081Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10919Issue Tracking, Third Party Advisory
- https://security.gentoo.org/glsa/202003-52
- https://security.netapp.com/advisory/ntap-20180814-0001/Third Party Advisory
- https://usn.ubuntu.com/3738-1/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4271Third Party Advisory
- https://www.samba.org/samba/security/CVE-2018-10919.htmlPatch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.