CVE-2023-0614
Summary
| CVE | CVE-2023-0614 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-04-03 23:15:00 UTC |
| Updated | 2023-11-07 04:01:00 UTC |
| Description | The fix in 4.6.16, 4.7.9, 4.8.4 and 4.9.7 for CVE-2018-10919 Confidential attribute disclosure vi LDAP filters was insufficient and an attacker may be able to obtain confidential BitLocker recovery keys from a Samba AD DC. |
Risk And Classification
Problem Types: CWE-312
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] Fedora 36 Update: samba-4.16.10-0.fc36 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| March 2023 Samba Vulnerabilities in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | |
| Samba: Multiple Vulnerabilities (GLSA 202309-06) — Gentoo security | GENTOO | security.gentoo.org | |
| Samba - Security Announcement Archive | MISC | www.samba.org | |
| [SECURITY] Fedora 36 Update: samba-4.16.10-0.fc36 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 183351 Debian Security Update for samba (CVE-2023-0614)
- 199268 Ubuntu Security Notification for Samba Vulnerabilities (USN-5993-1)
- 199270 Ubuntu Security Notification for ldb Vulnerability (USN-5992-1)
- 283844 Fedora Security Update for libldb (FEDORA-2023-fca3bfed78)
- 283895 Fedora Security Update for libldb (FEDORA-2023-1c172e3264)
- 284210 Fedora Security Update for libldb (FEDORA-2023-7ac413b969)
- 285322 Fedora Security Update for libldb (FEDORA-2023-8892fc09e9)
- 355404 Amazon Linux Security Advisory for libldb : ALAS2023-2023-187
- 355410 Amazon Linux Security Advisory for samba : ALAS2023-2023-190
- 355418 Amazon Linux Security Advisory for samba : ALAS2023-2023-206
- 673748 EulerOS Security Update for libldb (EulerOS-SA-2023-2650)
- 673860 EulerOS Security Update for libldb (EulerOS-SA-2023-2692)
- 691110 Free Berkeley Software Distribution (FreeBSD) Security Update for samba (e86b8e4d-d551-11ed-8d1e-005056a311d1)
- 710751 Gentoo Linux Samba Multiple Vulnerabilities (GLSA 202309-06)
- 753866 SUSE Enterprise Linux Security Update for ldb, samba (SUSE-SU-2023:1687-1)