UBUNTU-CVE-2018-14628

Source
https://ubuntu.com/security/CVE-2018-14628
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-14628.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2018-14628
Related
Published
2023-01-17T18:15:00Z
Modified
2024-10-15T14:06:32Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

An information leak vulnerability was discovered in Samba's LDAP server. Due to missing access control checks, an authenticated but unprivileged attacker could discover the names and preserved attributes of deleted objects in the LDAP store.

References

Affected packages

Ubuntu:Pro:14.04:LTS / samba

Package

Name
samba
Purl
pkg:deb/ubuntu/samba?arch=src?distro=trusty/esm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2:3.*

2:3.6.18-1ubuntu3

2:4.*

2:4.0.10+dfsg-4ubuntu2
2:4.0.13+dfsg-1ubuntu1
2:4.1.3+dfsg-2ubuntu2
2:4.1.3+dfsg-2ubuntu3
2:4.1.3+dfsg-2ubuntu4
2:4.1.3+dfsg-2ubuntu5
2:4.1.6+dfsg-1ubuntu1
2:4.1.6+dfsg-1ubuntu2
2:4.1.6+dfsg-1ubuntu2.14.04.1
2:4.1.6+dfsg-1ubuntu2.14.04.2
2:4.1.6+dfsg-1ubuntu2.14.04.3
2:4.1.6+dfsg-1ubuntu2.14.04.4
2:4.1.6+dfsg-1ubuntu2.14.04.5
2:4.1.6+dfsg-1ubuntu2.14.04.7
2:4.1.6+dfsg-1ubuntu2.14.04.8
2:4.1.6+dfsg-1ubuntu2.14.04.9
2:4.1.6+dfsg-1ubuntu2.14.04.11
2:4.1.6+dfsg-1ubuntu2.14.04.12
2:4.1.6+dfsg-1ubuntu2.14.04.13
2:4.3.8+dfsg-0ubuntu0.14.04.2
2:4.3.9+dfsg-0ubuntu0.14.04.1
2:4.3.9+dfsg-0ubuntu0.14.04.3
2:4.3.11+dfsg-0ubuntu0.14.04.1
2:4.3.11+dfsg-0ubuntu0.14.04.2
2:4.3.11+dfsg-0ubuntu0.14.04.3
2:4.3.11+dfsg-0ubuntu0.14.04.4
2:4.3.11+dfsg-0ubuntu0.14.04.6
2:4.3.11+dfsg-0ubuntu0.14.04.7
2:4.3.11+dfsg-0ubuntu0.14.04.8
2:4.3.11+dfsg-0ubuntu0.14.04.9
2:4.3.11+dfsg-0ubuntu0.14.04.10
2:4.3.11+dfsg-0ubuntu0.14.04.11
2:4.3.11+dfsg-0ubuntu0.14.04.12
2:4.3.11+dfsg-0ubuntu0.14.04.13
2:4.3.11+dfsg-0ubuntu0.14.04.14
2:4.3.11+dfsg-0ubuntu0.14.04.16
2:4.3.11+dfsg-0ubuntu0.14.04.17
2:4.3.11+dfsg-0ubuntu0.14.04.19
2:4.3.11+dfsg-0ubuntu0.14.04.20
2:4.3.11+dfsg-0ubuntu0.14.04.20+esm2
2:4.3.11+dfsg-0ubuntu0.14.04.20+esm3
2:4.3.11+dfsg-0ubuntu0.14.04.20+esm4
2:4.3.11+dfsg-0ubuntu0.14.04.20+esm6
2:4.3.11+dfsg-0ubuntu0.14.04.20+esm7
2:4.3.11+dfsg-0ubuntu0.14.04.20+esm8
2:4.3.11+dfsg-0ubuntu0.14.04.20+esm9
2:4.3.11+dfsg-0ubuntu0.14.04.20+esm11
2:4.3.11+dfsg-0ubuntu0.14.04.20+esm12

Ecosystem specific

{
    "ubuntu_priority": "low",
    "priority_reason": "minor information leak"
}

Ubuntu:Pro:16.04:LTS / samba

Package

Name
samba
Purl
pkg:deb/ubuntu/samba?arch=src?distro=esm-infra/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2:4.*

2:4.1.17+dfsg-4ubuntu2
2:4.1.20+dfsg-1ubuntu1
2:4.1.20+dfsg-1ubuntu2
2:4.1.20+dfsg-1ubuntu3
2:4.1.20+dfsg-1ubuntu5
2:4.3.3+dfsg-1ubuntu1
2:4.3.3+dfsg-1ubuntu2
2:4.3.3+dfsg-1ubuntu3
2:4.3.6+dfsg-1ubuntu1
2:4.3.8+dfsg-0ubuntu1
2:4.3.9+dfsg-0ubuntu0.16.04.1
2:4.3.9+dfsg-0ubuntu0.16.04.2
2:4.3.9+dfsg-0ubuntu0.16.04.3
2:4.3.11+dfsg-0ubuntu0.16.04.1
2:4.3.11+dfsg-0ubuntu0.16.04.3
2:4.3.11+dfsg-0ubuntu0.16.04.5
2:4.3.11+dfsg-0ubuntu0.16.04.6
2:4.3.11+dfsg-0ubuntu0.16.04.7
2:4.3.11+dfsg-0ubuntu0.16.04.8
2:4.3.11+dfsg-0ubuntu0.16.04.9
2:4.3.11+dfsg-0ubuntu0.16.04.10
2:4.3.11+dfsg-0ubuntu0.16.04.11
2:4.3.11+dfsg-0ubuntu0.16.04.12
2:4.3.11+dfsg-0ubuntu0.16.04.13
2:4.3.11+dfsg-0ubuntu0.16.04.15
2:4.3.11+dfsg-0ubuntu0.16.04.16
2:4.3.11+dfsg-0ubuntu0.16.04.17
2:4.3.11+dfsg-0ubuntu0.16.04.18
2:4.3.11+dfsg-0ubuntu0.16.04.19
2:4.3.11+dfsg-0ubuntu0.16.04.20
2:4.3.11+dfsg-0ubuntu0.16.04.21
2:4.3.11+dfsg-0ubuntu0.16.04.23
2:4.3.11+dfsg-0ubuntu0.16.04.24
2:4.3.11+dfsg-0ubuntu0.16.04.25
2:4.3.11+dfsg-0ubuntu0.16.04.26
2:4.3.11+dfsg-0ubuntu0.16.04.27
2:4.3.11+dfsg-0ubuntu0.16.04.28
2:4.3.11+dfsg-0ubuntu0.16.04.29
2:4.3.11+dfsg-0ubuntu0.16.04.30
2:4.3.11+dfsg-0ubuntu0.16.04.31
2:4.3.11+dfsg-0ubuntu0.16.04.32
2:4.3.11+dfsg-0ubuntu0.16.04.34
2:4.3.11+dfsg-0ubuntu0.16.04.34+esm1

Ecosystem specific

{
    "ubuntu_priority": "low",
    "priority_reason": "minor information leak"
}

Ubuntu:Pro:18.04:LTS / samba

Package

Name
samba
Purl
pkg:deb/ubuntu/samba?arch=src?distro=esm-infra/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2:4.*

2:4.6.7+dfsg-1ubuntu3
2:4.7.1+dfsg-1ubuntu1
2:4.7.3+dfsg-1ubuntu1
2:4.7.4+dfsg-1ubuntu1
2:4.7.6+dfsg~ubuntu-0ubuntu1
2:4.7.6+dfsg~ubuntu-0ubuntu2
2:4.7.6+dfsg~ubuntu-0ubuntu2.2
2:4.7.6+dfsg~ubuntu-0ubuntu2.4
2:4.7.6+dfsg~ubuntu-0ubuntu2.5
2:4.7.6+dfsg~ubuntu-0ubuntu2.6
2:4.7.6+dfsg~ubuntu-0ubuntu2.7
2:4.7.6+dfsg~ubuntu-0ubuntu2.9
2:4.7.6+dfsg~ubuntu-0ubuntu2.10
2:4.7.6+dfsg~ubuntu-0ubuntu2.11
2:4.7.6+dfsg~ubuntu-0ubuntu2.13
2:4.7.6+dfsg~ubuntu-0ubuntu2.14
2:4.7.6+dfsg~ubuntu-0ubuntu2.15
2:4.7.6+dfsg~ubuntu-0ubuntu2.16
2:4.7.6+dfsg~ubuntu-0ubuntu2.17
2:4.7.6+dfsg~ubuntu-0ubuntu2.18
2:4.7.6+dfsg~ubuntu-0ubuntu2.19
2:4.7.6+dfsg~ubuntu-0ubuntu2.20
2:4.7.6+dfsg~ubuntu-0ubuntu2.21
2:4.7.6+dfsg~ubuntu-0ubuntu2.23
2:4.7.6+dfsg~ubuntu-0ubuntu2.24
2:4.7.6+dfsg~ubuntu-0ubuntu2.26
2:4.7.6+dfsg~ubuntu-0ubuntu2.27
2:4.7.6+dfsg~ubuntu-0ubuntu2.28
2:4.7.6+dfsg~ubuntu-0ubuntu2.29

Ecosystem specific

{
    "ubuntu_priority": "low",
    "priority_reason": "minor information leak"
}

Ubuntu:20.04:LTS / samba

Package

Name
samba
Purl
pkg:deb/ubuntu/samba?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2:4.*

2:4.10.7+dfsg-0ubuntu2
2:4.10.7+dfsg-0ubuntu3
2:4.11.1+dfsg-3ubuntu1
2:4.11.1+dfsg-3ubuntu2
2:4.11.1+dfsg-3ubuntu4
2:4.11.5+dfsg-1ubuntu1
2:4.11.5+dfsg-1ubuntu2
2:4.11.6+dfsg-0ubuntu1
2:4.11.6+dfsg-0ubuntu1.1
2:4.11.6+dfsg-0ubuntu1.2
2:4.11.6+dfsg-0ubuntu1.3
2:4.11.6+dfsg-0ubuntu1.4
2:4.11.6+dfsg-0ubuntu1.5
2:4.11.6+dfsg-0ubuntu1.6
2:4.11.6+dfsg-0ubuntu1.8
2:4.11.6+dfsg-0ubuntu1.9
2:4.11.6+dfsg-0ubuntu1.10
2:4.13.14+dfsg-0ubuntu0.20.04.1
2:4.13.14+dfsg-0ubuntu0.20.04.2
2:4.13.14+dfsg-0ubuntu0.20.04.3
2:4.13.14+dfsg-0ubuntu0.20.04.4
2:4.13.17~dfsg-0ubuntu0.21.04.1
2:4.13.17~dfsg-0ubuntu0.21.04.2
2:4.13.17~dfsg-0ubuntu1.20.04.1
2:4.13.17~dfsg-0ubuntu1.20.04.2
2:4.13.17~dfsg-0ubuntu1.20.04.4
2:4.13.17~dfsg-0ubuntu1.20.04.5
2:4.15.13+dfsg-0ubuntu0.20.04.1
2:4.15.13+dfsg-0ubuntu0.20.04.2
2:4.15.13+dfsg-0ubuntu0.20.04.3
2:4.15.13+dfsg-0ubuntu0.20.04.4
2:4.15.13+dfsg-0ubuntu0.20.04.5
2:4.15.13+dfsg-0ubuntu0.20.04.6
2:4.15.13+dfsg-0ubuntu0.20.04.7

Ecosystem specific

{
    "ubuntu_priority": "low",
    "priority_reason": "minor information leak"
}

Ubuntu:22.04:LTS / samba

Package

Name
samba
Purl
pkg:deb/ubuntu/samba?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2:4.*

2:4.13.5+dfsg-2ubuntu2
2:4.13.5+dfsg-2ubuntu3
2:4.13.14+dfsg-0ubuntu1
2:4.13.14+dfsg-0ubuntu2
2:4.15.5~dfsg-0ubuntu1
2:4.15.5~dfsg-0ubuntu2
2:4.15.5~dfsg-0ubuntu4
2:4.15.5~dfsg-0ubuntu5
2:4.15.5~dfsg-0ubuntu5.1
2:4.15.9+dfsg-0ubuntu0.2
2:4.15.9+dfsg-0ubuntu0.3
2:4.15.13+dfsg-0ubuntu1
2:4.15.13+dfsg-0ubuntu1.1
2:4.15.13+dfsg-0ubuntu1.2
2:4.15.13+dfsg-0ubuntu1.3
2:4.15.13+dfsg-0ubuntu1.4
2:4.15.13+dfsg-0ubuntu1.5
2:4.15.13+dfsg-0ubuntu1.6

Ecosystem specific

{
    "ubuntu_priority": "low",
    "priority_reason": "minor information leak"
}

Ubuntu:24.04:LTS / samba

Package

Name
samba
Purl
pkg:deb/ubuntu/samba?arch=src?distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2:4.19.4+dfsg-3ubuntu1

Affected versions

2:4.*

2:4.18.6+dfsg-1ubuntu2
2:4.18.6+dfsg-1ubuntu2.1
2:4.18.6+dfsg-1ubuntu2.2

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "low",
    "binaries": [
        {
            "binary_version": "2:4.19.4+dfsg-3ubuntu1",
            "binary_name": "ctdb"
        },
        {
            "binary_version": "2:4.19.4+dfsg-3ubuntu1",
            "binary_name": "ctdb-dbgsym"
        },
        {
            "binary_version": "2:2.8.0+samba4.19.4+dfsg-3ubuntu1",
            "binary_name": "ldb-tools"
        },
        {
            "binary_version": "2:2.8.0+samba4.19.4+dfsg-3ubuntu1",
            "binary_name": "ldb-tools-dbgsym"
        },
        {
            "binary_version": "2:2.8.0+samba4.19.4+dfsg-3ubuntu1",
            "binary_name": "libldb-dev"
        },
        {
            "binary_version": "2:2.8.0+samba4.19.4+dfsg-3ubuntu1",
            "binary_name": "libldb2"
        },
        {
            "binary_version": "2:2.8.0+samba4.19.4+dfsg-3ubuntu1",
            "binary_name": "libldb2-dbgsym"
        },
        {
            "binary_version": "2:4.19.4+dfsg-3ubuntu1",
            "binary_name": "libnss-winbind"
        },
        {
            "binary_version": "2:4.19.4+dfsg-3ubuntu1",
            "binary_name": "libnss-winbind-dbgsym"
        },
        {
            "binary_version": "2:4.19.4+dfsg-3ubuntu1",
            "binary_name": "libpam-winbind"
        },
        {
            "binary_version": "2:4.19.4+dfsg-3ubuntu1",
            "binary_name": "libpam-winbind-dbgsym"
        },
        {
            "binary_version": "2:4.19.4+dfsg-3ubuntu1",
            "binary_name": "libsmbclient"
        },
        {
            "binary_version": "2:4.19.4+dfsg-3ubuntu1",
            "binary_name": "libsmbclient-dbgsym"
        },
        {
            "binary_version": "2:4.19.4+dfsg-3ubuntu1",
            "binary_name": "libsmbclient-dev"
        },
        {
            "binary_version": "2:4.19.4+dfsg-3ubuntu1",
            "binary_name": "libwbclient-dev"
        },
        {
            "binary_version": "2:4.19.4+dfsg-3ubuntu1",
            "binary_name": "libwbclient0"
        },
        {
            "binary_version": "2:4.19.4+dfsg-3ubuntu1",
            "binary_name": "libwbclient0-dbgsym"
        },
        {
            "binary_version": "2:2.8.0+samba4.19.4+dfsg-3ubuntu1",
            "binary_name": "python3-ldb"
        },
        {
            "binary_version": "2:2.8.0+samba4.19.4+dfsg-3ubuntu1",
            "binary_name": "python3-ldb-dbgsym"
        },
        {
            "binary_version": "2:2.8.0+samba4.19.4+dfsg-3ubuntu1",
            "binary_name": "python3-ldb-dev"
        },
        {
            "binary_version": "2:4.19.4+dfsg-3ubuntu1",
            "binary_name": "python3-samba"
        },
        {
            "binary_version": "2:4.19.4+dfsg-3ubuntu1",
            "binary_name": "python3-samba-dbgsym"
        },
        {
            "binary_version": "2:4.19.4+dfsg-3ubuntu1",
            "binary_name": "registry-tools"
        },
        {
            "binary_version": "2:4.19.4+dfsg-3ubuntu1",
            "binary_name": "registry-tools-dbgsym"
        },
        {
            "binary_version": "2:4.19.4+dfsg-3ubuntu1",
            "binary_name": "samba"
        },
        {
            "binary_version": "2:4.19.4+dfsg-3ubuntu1",
            "binary_name": "samba-ad-dc"
        },
        {
            "binary_version": "2:4.19.4+dfsg-3ubuntu1",
            "binary_name": "samba-ad-provision"
        },
        {
            "binary_version": "2:4.19.4+dfsg-3ubuntu1",
            "binary_name": "samba-common"
        },
        {
            "binary_version": "2:4.19.4+dfsg-3ubuntu1",
            "binary_name": "samba-common-bin"
        },
        {
            "binary_version": "2:4.19.4+dfsg-3ubuntu1",
            "binary_name": "samba-common-bin-dbgsym"
        },
        {
            "binary_version": "2:4.19.4+dfsg-3ubuntu1",
            "binary_name": "samba-dbgsym"
        },
        {
            "binary_version": "2:4.19.4+dfsg-3ubuntu1",
            "binary_name": "samba-dev"
        },
        {
            "binary_version": "2:4.19.4+dfsg-3ubuntu1",
            "binary_name": "samba-dsdb-modules"
        },
        {
            "binary_version": "2:4.19.4+dfsg-3ubuntu1",
            "binary_name": "samba-dsdb-modules-dbgsym"
        },
        {
            "binary_version": "2:4.19.4+dfsg-3ubuntu1",
            "binary_name": "samba-libs"
        },
        {
            "binary_version": "2:4.19.4+dfsg-3ubuntu1",
            "binary_name": "samba-libs-dbgsym"
        },
        {
            "binary_version": "2:4.19.4+dfsg-3ubuntu1",
            "binary_name": "samba-testsuite"
        },
        {
            "binary_version": "2:4.19.4+dfsg-3ubuntu1",
            "binary_name": "samba-testsuite-dbgsym"
        },
        {
            "binary_version": "2:4.19.4+dfsg-3ubuntu1",
            "binary_name": "samba-vfs-modules"
        },
        {
            "binary_version": "2:4.19.4+dfsg-3ubuntu1",
            "binary_name": "samba-vfs-modules-dbgsym"
        },
        {
            "binary_version": "2:4.19.4+dfsg-3ubuntu1",
            "binary_name": "samba-vfs-modules-extra"
        },
        {
            "binary_version": "2:4.19.4+dfsg-3ubuntu1",
            "binary_name": "samba-vfs-modules-extra-dbgsym"
        },
        {
            "binary_version": "2:4.19.4+dfsg-3ubuntu1",
            "binary_name": "smbclient"
        },
        {
            "binary_version": "2:4.19.4+dfsg-3ubuntu1",
            "binary_name": "smbclient-dbgsym"
        },
        {
            "binary_version": "2:4.19.4+dfsg-3ubuntu1",
            "binary_name": "winbind"
        },
        {
            "binary_version": "2:4.19.4+dfsg-3ubuntu1",
            "binary_name": "winbind-dbgsym"
        }
    ],
    "priority_reason": "minor information leak"
}