An information leak vulnerability was discovered in Samba's LDAP server. Due to missing access control checks, an authenticated but unprivileged attacker could discover the names and preserved attributes of deleted objects in the LDAP store.
References
Link | Resource |
---|---|
https://bugzilla.samba.org/show_bug.cgi?id=13595 | Exploit Issue Tracking Patch Vendor Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=1625445 | Exploit Issue Tracking Patch Third Party Advisory |
Information
Published : 2023-01-17 10:15
Updated : 2023-01-24 12:03
NVD link : CVE-2018-14628
Mitre link : CVE-2018-14628
JSON object : View
CWE
CWE-862
Missing Authorization
Products Affected
fedoraproject
- fedora
samba
- samba