VulnerabilityAnalyzed
CVE-2018-14628
An information leak vulnerability was discovered in Samba's LDAP server.
MEDIUM 4.3EPSS 1.17%
Does this matter?
Lower severity and a low EPSS score (1.17%). Track it; it rarely justifies an emergency change on its own.
Description
An information leak vulnerability was discovered in Samba's LDAP server. Due to missing access control checks, an authenticated but unprivileged attacker could discover the names and preserved attributes of deleted objects in the LDAP store.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.17% probability · 66th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-862
- Affected
- samba/samba · fedoraproject/fedora
- Source
- secalert@redhat.com
References
- http://www.openwall.com/lists/oss-security/2023/11/28/4Mailing List
- https://bugzilla.redhat.com/show_bug.cgi?id=1625445Exploit, Issue Tracking, Patch, Third Party Advisory
- https://bugzilla.samba.org/show_bug.cgi?id=13595Exploit, Issue Tracking, Patch, Vendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6DK57HQRTCDOZDIIICYWQ4Z5IQXTWVVW/Patch, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ACVMYEP5KJRL3FWSCZW2MQZ26IVPXY62/Patch, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2023/11/28/4Mailing List
- https://bugzilla.redhat.com/show_bug.cgi?id=1625445Exploit, Issue Tracking, Patch, Third Party Advisory
- https://bugzilla.samba.org/show_bug.cgi?id=13595Exploit, Issue Tracking, Patch, Vendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6DK57HQRTCDOZDIIICYWQ4Z5IQXTWVVW/Patch, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ACVMYEP5KJRL3FWSCZW2MQZ26IVPXY62/Patch, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20230223-0008/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.