CVE-2018-10919: Infoleak
Last updated 25 August 2025
Other sources
The Samba Active Directory LDAP server was vulnerable to an information disclosure flaw because of missing access control checks. An authenticated attacker could use this flaw to extract confidential attribute values using LDAP search expressions. Samba versions before 4.6.16, 4.7.9 and 4.8.4 are vulnerable.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-10919?
CVE-2018-10919 is a vulnerability in the Samba Active Directory LDAP server that allows an authenticated attacker to extract confidential attribute values using LDAP search expressions.
What is the severity of CVE-2018-10919?
CVE-2018-10919 has a severity rating of 6.5 (medium).
Which software versions are affected by CVE-2018-10919?
Samba versions before 4.6.16, 4.7.9, and 4.8.4 are vulnerable to CVE-2018-10919.
How can I fix CVE-2018-10919?
To fix CVE-2018-10919, update Samba to version 4.6.16, 4.7.9, or 4.8.4.
Where can I find more information about CVE-2018-10919?
You can find more information about CVE-2018-10919 on the Samba official website, the Debian security tracker, and the SecurityFocus website.