CVE-2018-10919 PUBLISHED

The Samba Active Directory LDAP server was vulnerable to an information disclosure flaw because of missing access control checks. An authenticated attacker could use this flaw to extract confidential attribute values using LDAP search expressions. Samba versions before 4.6.16, 4.7.9 and 4.8.4 are vulnerable.

EPSS 1.79% · 82.6th percentile

Risk Scores

EPSS Score
1.79%
82.6th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSsamba0, 2:4.1.17+dfsg-4ubuntu2, 2:4.1.20+dfsg-1ubuntu1
Ubuntu:14.04:LTSsamba2:4.3.11+dfsg-0ubuntu0.14.04.2, 2:4.3.11+dfsg-0ubuntu0.14.04.3, 2:4.3.11+dfsg-0ubuntu0.14.04.4
Ubuntu:18.04:LTSsamba0, 2:4.6.7+dfsg-1ubuntu3, 2:4.7.1+dfsg-1ubuntu1

Timeline

References

Open in Interactive Console →