Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-14628

Опубликовано: 17 янв. 2023
Источник: debian

Описание

An information leak vulnerability was discovered in Samba's LDAP server. Due to missing access control checks, an authenticated but unprivileged attacker could discover the names and preserved attributes of deleted objects in the LDAP store.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
sambafixed2:4.19.3+dfsg-1package
sambafixed2:4.17.12+dfsg-0+deb12u3bookwormpackage
sambaignoredbullseyepackage
sambaignoredbusterpackage

Примечания

  • https://bugzilla.samba.org/show_bug.cgi?id=13595

  • https://www.samba.org/samba/security/CVE-2018-14628.html

  • Fixes for 4.17: https://gitlab.com/samba-team/lts-community/samba/-/merge_requests/3

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 3 лет назад

An information leak vulnerability was discovered in Samba's LDAP server. Due to missing access control checks, an authenticated but unprivileged attacker could discover the names and preserved attributes of deleted objects in the LDAP store.

CVSS3: 4.3
redhat
больше 4 лет назад

An information leak vulnerability was discovered in Samba's LDAP server. Due to missing access control checks, an authenticated but unprivileged attacker could discover the names and preserved attributes of deleted objects in the LDAP store.

CVSS3: 4.3
nvd
больше 3 лет назад

An information leak vulnerability was discovered in Samba's LDAP server. Due to missing access control checks, an authenticated but unprivileged attacker could discover the names and preserved attributes of deleted objects in the LDAP store.

CVSS3: 4.3
msrc
10 месяцев назад

An information leak vulnerability was discovered in Samba's LDAP server. Due to missing access control checks, an authenticated but unprivileged attacker could discover the names and preserved attributes of deleted objects in the LDAP store.

CVSS3: 4.3
github
больше 3 лет назад

An information leak vulnerability was discovered in Samba's LDAP server. Due to missing access control checks, an authenticated but unprivileged attacker could discover the names and preserved attributes of deleted objects in the LDAP store.