First published: Mon Apr 03 2023(Updated: )
The fix in 4.6.16, 4.7.9, 4.8.4 and 4.9.7 for CVE-2018-10919 Confidential attribute disclosure vi LDAP filters was insufficient and an attacker may be able to obtain confidential BitLocker recovery keys from a Samba AD DC.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samba Samba | >=4.0.0<4.16.10 | |
Samba Samba | >=4.17.0<4.17.7 | |
Samba Samba | =4.18.0 | |
Samba Samba | =4.18.0-rc1 | |
Samba Samba | =4.18.0-rc2 | |
Samba Samba | =4.18.0-rc3 | |
Samba Samba | =4.18.0-rc4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-0614 refers to a vulnerability in Samba that allows an attacker to obtain confidential BitLocker recovery keys from a Samba AD DC.
CVE-2023-0614 has a severity score of 6.5 out of 10.
Samba versions from 4.0.0 to 4.16.10, 4.17.0 to 4.17.7, 4.18.0-rc1, 4.18.0-rc2, 4.18.0-rc3, and 4.18.0-rc4 are affected by CVE-2023-0614.
To fix CVE-2023-0614, update Samba to version 4.6.16, 4.7.9, 4.8.4, or 4.9.7.
You can find more information about CVE-2023-0614 at the following references: [link1], [link2], [link3].