Search CVE reports


Toggle filters

21 – 30 of 206 results


CVE-2023-4154

Medium priority

Some fixes available 9 of 12

A design flaw was found in Samba's DirSync control implementation, which exposes passwords and secrets in Active Directory to privileged users and Read-Only Domain Controllers (RODCs). This flaw allows RODCs and users possessing...

1 affected package

samba

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba Fixed Fixed Fixed Fixed Needs evaluation
Show less packages

CVE-2023-4091

Medium priority

Some fixes available 9 of 12

A vulnerability was discovered in Samba, where the flaw allows SMB clients to truncate files, even with read-only permissions when the Samba VFS module "acl_xattr" is configured with "acl_xattr:ignore system acls = yes". The SMB...

1 affected package

samba

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba Fixed Fixed Fixed Fixed Needs evaluation
Show less packages

CVE-2023-3961

Medium priority
Not affected

A path traversal vulnerability was identified in Samba when processing client pipe names connecting to Unix domain sockets within a private directory. Samba typically uses this mechanism to connect SMB clients to remote procedure...

1 affected package

samba

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba Not affected Not affected Not affected
Show less packages

CVE-2023-34968

Medium priority

Some fixes available 10 of 13

A path disclosure vulnerability was found in Samba. As part of the Spotlight protocol, Samba discloses the server-side absolute path of shares, files, and directories in the results for search queries. This flaw allows a malicious...

1 affected package

samba

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba Fixed Fixed Fixed Fixed Needs evaluation
Show less packages

CVE-2023-34967

Medium priority
Fixed

A Type Confusion vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing Spotlight mdssvc RPC packets, one encoded data structure is a key-value style dictionary where the keys are character strings, and...

1 affected package

samba

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba Fixed Fixed Not affected
Show less packages

CVE-2023-34966

Medium priority
Fixed

An infinite loop vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing Spotlight mdssvc RPC packets sent by the client, the core unmarshalling function sl_unpack_loop() did not validate a field in the...

1 affected package

samba

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba Fixed Fixed Fixed Fixed
Show less packages

CVE-2023-3347

Medium priority
Fixed

A vulnerability was found in Samba's SMB2 packet signing mechanism. The SMB2 packet signing is not enforced if an admin configured "server signing = required" or for SMB2 connections to Domain Controllers where SMB2 packet signing...

1 affected package

samba

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba Not affected Not affected Not affected
Show less packages

CVE-2022-2127

Medium priority

Some fixes available 10 of 13

An out-of-bounds read vulnerability was found in Samba due to insufficient length checks in winbindd_pam_auth_crap.c. When performing NTLM authentication, the client replies to cryptographic challenges back to the server. These...

1 affected package

samba

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba Fixed Fixed Fixed Fixed Needs evaluation
Show less packages

CVE-2023-0922

Medium priority

Some fixes available 10 of 13

The Samba AD DC administration tool, when operating against a remote LDAP server, will by default send new or reset passwords over a signed-only connection.

1 affected package

samba

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba Fixed Fixed Fixed Fixed Vulnerable
Show less packages

CVE-2023-0614

Medium priority

Some fixes available 12 of 18

The fix in 4.6.16, 4.7.9, 4.8.4 and 4.9.7 for CVE-2018-10919 Confidential attribute disclosure vi LDAP filters was insufficient and an attacker may be able to obtain confidential BitLocker recovery keys from a Samba AD DC.

2 affected packages

ldb, samba

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ldb Not in release Not in release Fixed Fixed Vulnerable
samba Fixed Fixed Fixed Fixed Vulnerable
Show less packages