Samba Releases Security Updates
Security updates address one High and two Medium severity vulnerabilities in multiple versions of Samba
Summary
Security updates address one High and two Medium severity vulnerabilities in multiple versions of Samba
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Samba has released security updates to address one High and two Medium severity vulnerabilities in multiple versions of Samba. The High severity vulnerability known as CVE-2023-0614 has a CVSSv3 score of 7.7 and relates to confidential attribute disclosure via LDAP filters. An attacker could obtain confidential BitLocker recovery keys from a Samba Active Directory Domain Controller (AD DC).
Remediation advice
Affected organisations are encouraged to review Samba's security advisories and to apply the relevant updates where applicable.
Remediation steps
| Type | Step |
|---|---|
| Patch |
CVE-2023-0225 | Samba AD DC "dnsHostname" attribute can be deleted by unprivileged authenticated users https://www.samba.org/samba/security/CVE-2023-0225.html |
| Patch |
CVE-2023-0922 | Samba AD DC admin tool samba-tool sends passwords in cleartext https://www.samba.org/samba/security/CVE-2023-0922.html |
| Patch |
CVE-2023-0614 | Access controlled AD LDAP attributes can be discovered https://www.samba.org/samba/security/CVE-2023-0614.html |
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 3 April 2023 12:53 pm