ZDI-23-1227: Samba Spotlight mdssvc RPC Request Infinite Loop Denial-of-Service Vulnerability
Published Aug 25, 2023
·Updated
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Samba. Authentication is not required to exploit this vulnerability.
Affected Software
1 affected component
Samba Samba
Event History
Aug 25, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-23-1227?
ZDI-23-1227 has a high severity rating due to its potential to create a denial-of-service condition.
2
How do I fix ZDI-23-1227?
To mitigate ZDI-23-1227, update your Samba installation to the latest version that addresses this vulnerability.
3
What type of attack can be executed using ZDI-23-1227?
ZDI-23-1227 allows attackers to perform remote denial-of-service attacks against vulnerable Samba installations.
4
Is authentication required to exploit ZDI-23-1227?
No, ZDI-23-1227 can be exploited without authentication.
5
Which software versions are affected by ZDI-23-1227?
ZDI-23-1227 affects various installations of Samba, but specific version details should be checked in the advisory.