Red Hat Bugzilla – Bug 1610645
CVE-2018-10919 samba: Confidential attribute disclosure via substring search
Last modified: 2018-09-25 23:39:50 EDT
When using custom LDAP attributes, Samba seems to recognize the searchFlags confidential flag on custom attributes and hides them from all non-admin users. However, the values of the attributes can still be guessed efficiently by brute forcing them one character after another in a wildcard search query.
External Reference: https://www.samba.org/samba/security/CVE-2018-10919.html
Created samba tracking bugs for this issue: Affects: fedora-all [bug 1617911]
Acknowledgments: Name: Phillip Kuhrt (the Samba project)