CVE-2018-14628

An information leak vulnerability was discovered in Samba's LDAP server. Due to missing access control checks, an authenticated but unprivileged attacker could discover the names and preserved attributes of deleted objects in the LDAP store.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*

History

22 Jan 2025, 16:10

Type Values Removed Values Added
References () http://www.openwall.com/lists/oss-security/2023/11/28/4 - () http://www.openwall.com/lists/oss-security/2023/11/28/4 - Mailing List
References () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6DK57HQRTCDOZDIIICYWQ4Z5IQXTWVVW/ - () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6DK57HQRTCDOZDIIICYWQ4Z5IQXTWVVW/ - Patch, Third Party Advisory
References () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ACVMYEP5KJRL3FWSCZW2MQZ26IVPXY62/ - () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ACVMYEP5KJRL3FWSCZW2MQZ26IVPXY62/ - Patch, Third Party Advisory
References () https://security.netapp.com/advisory/ntap-20230223-0008/ - () https://security.netapp.com/advisory/ntap-20230223-0008/ - Third Party Advisory

21 Nov 2024, 03:49

Type Values Removed Values Added
Summary
  • (es) Se descubrió una vulnerabilidad de fuga de información en el servidor LDAP de Samba. Debido a la falta de comprobaciones de control de acceso, un atacante autenticado pero sin privilegios podría descubrir los nombres y atributos conservados de los objetos eliminados en el almacén LDAP.
References
  • () https://security.netapp.com/advisory/ntap-20230223-0008/ -
References () http://www.openwall.com/lists/oss-security/2023/11/28/4 - () http://www.openwall.com/lists/oss-security/2023/11/28/4 -
References () https://bugzilla.redhat.com/show_bug.cgi?id=1625445 - Exploit, Issue Tracking, Patch, Third Party Advisory () https://bugzilla.redhat.com/show_bug.cgi?id=1625445 - Exploit, Issue Tracking, Patch, Third Party Advisory
References () https://bugzilla.samba.org/show_bug.cgi?id=13595 - Exploit, Issue Tracking, Patch, Vendor Advisory () https://bugzilla.samba.org/show_bug.cgi?id=13595 - Exploit, Issue Tracking, Patch, Vendor Advisory
References () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6DK57HQRTCDOZDIIICYWQ4Z5IQXTWVVW/ - () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6DK57HQRTCDOZDIIICYWQ4Z5IQXTWVVW/ -
References () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ACVMYEP5KJRL3FWSCZW2MQZ26IVPXY62/ - () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ACVMYEP5KJRL3FWSCZW2MQZ26IVPXY62/ -

04 Dec 2023, 03:15

Type Values Removed Values Added
References
  • () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ACVMYEP5KJRL3FWSCZW2MQZ26IVPXY62/ -

02 Dec 2023, 02:15

Type Values Removed Values Added
References
  • () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6DK57HQRTCDOZDIIICYWQ4Z5IQXTWVVW/ -

28 Nov 2023, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-01-17 18:15

Updated : 2025-01-22 16:10


NVD link : CVE-2018-14628

Mitre link : CVE-2018-14628

CVE.ORG link : CVE-2018-14628


JSON object : View

Products Affected

fedoraproject

  • fedora

samba

  • samba
CWE
CWE-862

Missing Authorization