Bug 56879 - samba: information disclosure (5.0)
samba: information disclosure (5.0)
Status: NEW
Product: UCS
Classification: Unclassified
Component: Samba4
UCS 5.0
Other Linux
: P5 normal (vote)
: ---
Assigned To: Samba maintainers
Samba maintainers
https://bugzilla.samba.org/show_bug.c...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2023-11-28 10:55 CET by Arvid Requate
Modified: 2023-11-28 10:59 CET (History)
0 users

See Also:
What kind of report is it?: Security Issue
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional): Security
Max CVSS v3 score: 4.3 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
requate: Patch_Available+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Arvid Requate univentionstaff 2023-11-28 10:55:56 CET
CVE-2018-14628: Unprivileged read of deleted object tombstones in AD LDAP server

Details: https://www.samba.org/samba/security/CVE-2018-14628.html

Semi-automatic adjustment of ACLs required on the "Deleted Objects" containers.
Maybe we can automate this for most cases, where people have not customized the DSACL of those (4) objects.
Comment 1 Arvid Requate univentionstaff 2023-11-28 10:59:21 CET
GitLab issue: https://git.knut.univention.de/univention/ucs/-/issues/1922