[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253164

 
 

909

 
 

197077

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2023-2023-206 --- samba

ID: oval:org.secpod.oval:def:19500236Date: (C)2024-01-04   (M)2024-01-04
Class: PATCHFamily: unix




An information leak vulnerability was discovered in Samba's LDAP server. Due to missing access control checks, an authenticated but unprivileged attacker could discover the names and preserved attributes of deleted objects in the LDAP store. A user with sufficient privileges to create a computer account, such as a user granted CreateChild permissions for computer objects, may potentially set arbitrary values on security-sensitive attributes of specific objects stored in Active Directory . Samba AD DC "dnsHostname" attribute can be deleted by unprivileged authenticated users. Access controlled AD LDAP attributes can be discovered Samba AD DC admin tool samba-tool sends passwords in cleartext

Platform:
Amazon Linux 2023
Product:
samba
libnetapi
libwbclient
libsmbclient
python3-samba
Reference:
ALAS2023-2023-206
CVE-2018-14628
CVE-2020-25720
CVE-2023-0225
CVE-2023-0614
CVE-2023-0922
CVE    5
CVE-2023-0225
CVE-2023-0614
CVE-2023-0922
CVE-2018-14628
...
CPE    4
cpe:/a:samba:samba
cpe:/a:python:python3-samba
cpe:/a:libwbclient:libwbclient
cpe:/a:libsmbclient:libsmbclient
...

© SecPod Technologies