CVE-2023-0614: Infoleak
Published Apr 3, 2023
·Updated
The fix in 4.6.16, 4.7.9, 4.8.4 and 4.9.7 for CVE-2018-10919 Confidential attribute disclosure vi LDAP filters was insufficient and an attacker may be able to obtain confidential BitLocker recovery keys from a Samba AD DC.
Affected Software
7 affected components
Samba Samba>=4.0.0<4.16.10
Samba Samba>=4.17.0<4.17.7
Samba Samba=4.18.0
Samba Samba=4.18.0-rc1
Samba Samba=4.18.0-rc2
Samba Samba=4.18.0-rc3
Samba Samba=4.18.0-rc4
Event History
Apr 3, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Nov 28, 57092
Event
via NVD·02:54 PM
Frequently Asked Questions
1
What is CVE-2023-0614?
CVE-2023-0614 refers to a vulnerability in Samba that allows an attacker to obtain confidential BitLocker recovery keys from a Samba AD DC.
2
How severe is CVE-2023-0614?
CVE-2023-0614 has a severity score of 6.5 out of 10.
3
Which versions of Samba are affected by CVE-2023-0614?
Samba versions from 4.0.0 to 4.16.10, 4.17.0 to 4.17.7, 4.18.0-rc1, 4.18.0-rc2, 4.18.0-rc3, and 4.18.0-rc4 are affected by CVE-2023-0614.
4
How can I fix CVE-2023-0614?
To fix CVE-2023-0614, update Samba to version 4.6.16, 4.7.9, 4.8.4, or 4.9.7.
5
Where can I find more information about CVE-2023-0614?
You can find more information about CVE-2023-0614 at the following references: [link1], [link2], [link3].