USN-6238-1
Dashboard / Vulnerabilities / USN-6238-1
USN-6238-1
Summary: samba vulnerabilities
Details: It was discovered that Samba incorrectly handled Winbind NTLM authentication responses. An attacker could possibly use this issue to cause Samba to crash, resulting in a denial of service. (CVE-2022-2127) Andreas Schneider discovered that Samba incorrectly enforced SMB2 packet signing. A remote attacker could possibly use this issue to obtain or modify sensitive information. This issue only affected Ubuntu 23.04. (CVE-2023-3347) Florent Saudel and Arnaud Gatignolof discovered that Samba incorrectly handled certain Spotlight requests. A remote attacker could possibly use this issue to cause Samba to consume resources, leading to a denial of service. (CVE-2023-34966, CVE-2023-34967) Ralph Boehme and Stefan Metzmacher discovered that Samba incorrectly handled paths returned by Spotlight requests. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2023-34968)
References: https://ubuntu.com/security/notices/USN-6238-1, https://ubuntu.com/security/CVE-2022-2127, https://ubuntu.com/security/CVE-2023-3347, https://ubuntu.com/security/CVE-2023-34966, https://ubuntu.com/security/CVE-2023-34967, https://ubuntu.com/security/CVE-2023-34968
Affected packages
Package
Name: samba
Purl: pkg:deb/ubuntu/samba@2:4.15.13+dfsg-0ubuntu0.20.04.3?arch=source&distro=focal
Affected ranges
Type: ECOSYSTEM
Events:
