UBUNTU-CVE-2023-4154
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-4154
UBUNTU-CVE-2023-4154
Summary:
Details: A design flaw was found in Samba's DirSync control implementation, which exposes passwords and secrets in Active Directory to privileged users and Read-Only Domain Controllers (RODCs). This flaw allows RODCs and users possessing the GET_CHANGES right to access all attributes, including sensitive secrets and passwords. Even in a default setup, RODC DC accounts, which should only replicate some passwords, can gain access to all domain secrets, including the vital krbtgt, effectively eliminating the RODC / DC distinction. Furthermore, the vulnerability fails to account for error conditions (fail open), like out-of-memory situations, potentially granting access to secret attributes, even under low-privileged attacker influence.
References: https://ubuntu.com/security/CVE-2023-4154, https://www.samba.org/samba/security/CVE-2023-4154.html, https://ubuntu.com/security/notices/USN-6425-1, https://ubuntu.com/security/notices/USN-6425-3, https://www.cve.org/CVERecord?id=CVE-2023-4154
Affected packages
Package
Name: samba
Purl: pkg:deb/ubuntu/samba@2:4.3.11+dfsg-0ubuntu0.14.04.20+esm15?arch=source&distro=esm-infra-legacy/trusty
Affected ranges
Type: ECOSYSTEM
Events:
