← Back

CVE-2018-14628

nvd nist
Published: Jan 17, 2023Modified: Jan 22, 2025

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Exploitability: 2.8 / Impact: 1.4
Source: NVD

Description

An information leak vulnerability was discovered in Samba's LDAP server. Due to missing access control checks, an authenticated but unprivileged attacker could discover the names and preserved attributes of deleted objects in the LDAP store.

Affected (3)

1 product
Samba
1 product
Fedora
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Samba
From 4.0.0 to 4.18.9
From 4.19.0 to 4.19.3
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 37

References (11)

Source: secalert@redhat.com
Mailing List
Source: secalert@redhat.com
ExploitIssue TrackingPatchThird Party Advisory
Source: secalert@redhat.com
ExploitIssue TrackingPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.