CVE-2023-0225
Summary
| CVE | CVE-2023-0225 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-04-03 23:15:00 UTC |
| Updated | 2023-09-17 09:15:00 UTC |
| Description | A flaw was found in Samba. An incomplete access check on dnsHostName allows authenticated but otherwise unprivileged users to delete this attribute from any object in the directory. |
Risk And Classification
Problem Types: CWE-732
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| March 2023 Samba Vulnerabilities in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | |
| Samba: Multiple Vulnerabilities (GLSA 202309-06) — Gentoo security | GENTOO | security.gentoo.org | |
| Samba - Security Announcement Archive | MISC | www.samba.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 183869 Debian Security Update for samba (CVE-2023-0225)
- 283844 Fedora Security Update for libldb (FEDORA-2023-fca3bfed78)
- 284210 Fedora Security Update for libldb (FEDORA-2023-7ac413b969)
- 285322 Fedora Security Update for libldb (FEDORA-2023-8892fc09e9)
- 355410 Amazon Linux Security Advisory for samba : ALAS2023-2023-190
- 355418 Amazon Linux Security Advisory for samba : ALAS2023-2023-206
- 503129 Alpine Linux Security Update for samba
- 505936 Alpine Linux Security Update for samba
- 691110 Free Berkeley Software Distribution (FreeBSD) Security Update for samba (e86b8e4d-d551-11ed-8d1e-005056a311d1)
- 710751 Gentoo Linux Samba Multiple Vulnerabilities (GLSA 202309-06)
- 753866 SUSE Enterprise Linux Security Update for ldb, samba (SUSE-SU-2023:1687-1)