Information disclosure in Samba - CVE-2018-10919

 

Information disclosure in Samba - CVE-2018-10919

Published: August 14, 2018


Vulnerability identifier: #VU14335
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-10919
CWE-ID: CWE-284
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to missing access control checks when displaying values of confidential attributes. A remote authenticated attacker can use LDAP search expression to  obtain both of attributes where the schema SEARCH_FLAG_CONFIDENTIAL (0x80) searchFlags bit and where an explicit Access Control Entry has been specified on the ntSecurityDescriptor.

Affected software

Samba
Debian Linux
Gentoo Linux
Slackware Linux
Opensuse
openEuler
Fedora
samba (Alpine package)
libldb
libldb-help
libldb-debuginfo
python3-ldb-devel
python-ldb-devel-common
python3-ldb
libldb-debugsource
libldb-devel
samba
RoboHelp

How to mitigate CVE-2018-10919

Update to version 4.6.16, 4.7.9 or 4.8.4.

Samba - addressed in versions 4.6.16, 4.7.9, 4.8.4
samba (Alpine package) - update to 4.5.16-r1
libldb - update to 1.4.0-3.fc28.1.3.5
libldb-help - addressed in versions 2.4.1-3, 2.6.1-2
libldb-debuginfo - addressed in versions 2.4.1-3, 2.6.1-2
python3-ldb-devel - addressed in versions 2.4.1-3, 2.6.1-2
python-ldb-devel-common - addressed in versions 2.4.1-3, 2.6.1-2
python3-ldb - addressed in versions 2.4.1-3, 2.6.1-2
libldb-debugsource - addressed in versions 2.4.1-3, 2.6.1-2
libldb-devel - addressed in versions 2.4.1-3, 2.6.1-2
libldb - addressed in versions 2.4.1-3, 2.6.1-2
samba - addressed in versions 4.7.9-0.fc27, 4.8.4-0.fc28

External References

Related Security Bulletins