CVE-2018-1140: Samba
Medium severity, CVSS 6.5. EPSS: 10.8% chance of exploitation in the next 30 days.
A missing input sanitization flaw was found in the implementation of LDP database used for the LDAP server. An attacker could use this flaw to cause a denial of service against a samba server, used as a Active Directory Domain Controller. All versions of Samba from 4.8.0 onwards are vulnerable
Affected products
- Samba Samba: from 4.8.0, before 4.8.4 (fixed in 4.8.4)
Published 2018-08-22. Last modified 2026-06-17.