SUSE update for samba



Published: 2023-10-12
Risk Medium
Patch available YES
Number of vulnerabilities 3
CVE-ID CVE-2023-4091
CVE-2023-4154
CVE-2023-42669
CWE-ID CWE-264
CWE-200
CWE-399
Exploitation vector Network
Public exploit N/A
Vulnerable software
Subscribe
SUSE Linux Enterprise Micro for Rancher
Operating systems & Components / Operating system

SUSE Linux Enterprise High Availability Extension 15
Operating systems & Components / Operating system

SUSE Linux Enterprise Micro
Operating systems & Components / Operating system

SUSE Linux Enterprise Server for SAP Applications 15
Operating systems & Components / Operating system

SUSE Linux Enterprise Server 15
Operating systems & Components / Operating system

SUSE Linux Enterprise Real Time 15
Operating systems & Components / Operating system

SUSE Linux Enterprise High Performance Computing 15
Operating systems & Components / Operating system

SUSE Linux Enterprise Desktop 15
Operating systems & Components / Operating system

Basesystem Module
Operating systems & Components / Operating system

SUSE Manager Retail Branch Server
Operating systems & Components / Operating system

SUSE Manager Server
Operating systems & Components / Operating system

SUSE Manager Proxy
Operating systems & Components / Operating system

openSUSE Leap
Operating systems & Components / Operating system

samba-libs-64bit
Operating systems & Components / Operating system package or component

samba-client-64bit
Operating systems & Components / Operating system package or component

samba-client-libs-64bit-debuginfo
Operating systems & Components / Operating system package or component

samba-ad-dc-libs-64bit
Operating systems & Components / Operating system package or component

samba-libs-python3-64bit
Operating systems & Components / Operating system package or component

samba-winbind-libs-64bit
Operating systems & Components / Operating system package or component

samba-libs-python3-64bit-debuginfo
Operating systems & Components / Operating system package or component

samba-client-64bit-debuginfo
Operating systems & Components / Operating system package or component

samba-client-libs-64bit
Operating systems & Components / Operating system package or component

samba-devel-64bit
Operating systems & Components / Operating system package or component

samba-winbind-libs-64bit-debuginfo
Operating systems & Components / Operating system package or component

samba-libs-64bit-debuginfo
Operating systems & Components / Operating system package or component

samba-ad-dc-libs-64bit-debuginfo
Operating systems & Components / Operating system package or component

libsamba-policy0-python3-64bit
Operating systems & Components / Operating system package or component

libsamba-policy0-python3-64bit-debuginfo
Operating systems & Components / Operating system package or component

samba-ceph-debuginfo
Operating systems & Components / Operating system package or component

samba-ceph
Operating systems & Components / Operating system package or component

samba-doc
Operating systems & Components / Operating system package or component

samba-winbind-libs-32bit
Operating systems & Components / Operating system package or component

samba-client-libs-32bit
Operating systems & Components / Operating system package or component

samba-libs-32bit
Operating systems & Components / Operating system package or component

samba-ad-dc-libs-32bit
Operating systems & Components / Operating system package or component

samba-devel-32bit
Operating systems & Components / Operating system package or component

samba-client-32bit
Operating systems & Components / Operating system package or component

samba-client-32bit-debuginfo
Operating systems & Components / Operating system package or component

samba-libs-32bit-debuginfo
Operating systems & Components / Operating system package or component

samba-libs-python3-32bit
Operating systems & Components / Operating system package or component

samba-ad-dc-libs-32bit-debuginfo
Operating systems & Components / Operating system package or component

samba-libs-python3-32bit-debuginfo
Operating systems & Components / Operating system package or component

libsamba-policy0-python3-32bit-debuginfo
Operating systems & Components / Operating system package or component

samba-client-libs-32bit-debuginfo
Operating systems & Components / Operating system package or component

libsamba-policy0-python3-32bit
Operating systems & Components / Operating system package or component

samba-winbind-libs-32bit-debuginfo
Operating systems & Components / Operating system package or component

samba-libs-debuginfo
Operating systems & Components / Operating system package or component

samba-client-libs-debuginfo
Operating systems & Components / Operating system package or component

samba-debugsource
Operating systems & Components / Operating system package or component

samba-libs-python3-debuginfo
Operating systems & Components / Operating system package or component

samba-client
Operating systems & Components / Operating system package or component

ctdb
Operating systems & Components / Operating system package or component

samba-winbind
Operating systems & Components / Operating system package or component

samba
Operating systems & Components / Operating system package or component

libsamba-policy-devel
Operating systems & Components / Operating system package or component

samba-test
Operating systems & Components / Operating system package or component

samba-python3-debuginfo
Operating systems & Components / Operating system package or component

samba-winbind-debuginfo
Operating systems & Components / Operating system package or component

samba-dsdb-modules
Operating systems & Components / Operating system package or component

samba-winbind-libs-debuginfo
Operating systems & Components / Operating system package or component

ctdb-pcp-pmda-debuginfo
Operating systems & Components / Operating system package or component

samba-devel
Operating systems & Components / Operating system package or component

ctdb-pcp-pmda
Operating systems & Components / Operating system package or component

samba-libs-python3
Operating systems & Components / Operating system package or component

samba-libs
Operating systems & Components / Operating system package or component

samba-debuginfo
Operating systems & Components / Operating system package or component

libsamba-policy-python3-devel
Operating systems & Components / Operating system package or component

libsamba-policy0-python3
Operating systems & Components / Operating system package or component

samba-dsdb-modules-debuginfo
Operating systems & Components / Operating system package or component

ctdb-debuginfo
Operating systems & Components / Operating system package or component

samba-ldb-ldap
Operating systems & Components / Operating system package or component

samba-test-debuginfo
Operating systems & Components / Operating system package or component

samba-ad-dc
Operating systems & Components / Operating system package or component

samba-winbind-libs
Operating systems & Components / Operating system package or component

samba-gpupdate
Operating systems & Components / Operating system package or component

samba-ldb-ldap-debuginfo
Operating systems & Components / Operating system package or component

samba-client-debuginfo
Operating systems & Components / Operating system package or component

samba-tool
Operating systems & Components / Operating system package or component

samba-ad-dc-libs-debuginfo
Operating systems & Components / Operating system package or component

libsamba-policy0-python3-debuginfo
Operating systems & Components / Operating system package or component

samba-python3
Operating systems & Components / Operating system package or component

samba-client-libs
Operating systems & Components / Operating system package or component

samba-ad-dc-libs
Operating systems & Components / Operating system package or component

samba-ad-dc-debuginfo
Operating systems & Components / Operating system package or component

Vendor SUSE

Security Bulletin

This security bulletin contains information about 3 vulnerabilities.

1) Permissions, Privileges, and Access Controls

EUVDB-ID: #VU81872

Risk: Low

CVSSv3.1: 3.8 [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2023-4091

CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls

Exploit availability: No

Description

The vulnerability allows a remote user to truncate read-only files.

The vulnerability exists due to an error in the way SMB protocol implementation in Samba handles file operations. A remote user can request read-only access to files and then truncate them to 0 bytes by opening files with OVERWRITE disposition when using the acl_xattr Samba VFS module with the smb.conf setting "acl_xattr:ignore system acls = yes".

Mitigation

Update the affected package samba to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Micro for Rancher: 5.3 - 5.4

SUSE Linux Enterprise High Availability Extension 15: SP4

SUSE Linux Enterprise Micro: 5.3 - 5.4

SUSE Linux Enterprise Server for SAP Applications 15: SP4

SUSE Linux Enterprise Server 15: SP4

SUSE Linux Enterprise Real Time 15: SP4

SUSE Linux Enterprise High Performance Computing 15: SP4

SUSE Linux Enterprise Desktop 15: SP4

Basesystem Module: 15-SP4

SUSE Manager Retail Branch Server: 4.3

SUSE Manager Server: 4.3

SUSE Manager Proxy: 4.3

openSUSE Leap: 15.4

samba-libs-64bit: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-client-64bit: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-client-libs-64bit-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-ad-dc-libs-64bit: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-libs-python3-64bit: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-winbind-libs-64bit: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-libs-python3-64bit-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-client-64bit-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-client-libs-64bit: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-devel-64bit: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-winbind-libs-64bit-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-libs-64bit-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-ad-dc-libs-64bit-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

libsamba-policy0-python3-64bit: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

libsamba-policy0-python3-64bit-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-ceph-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-ceph: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-doc: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-winbind-libs-32bit: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-client-libs-32bit: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-libs-32bit: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-ad-dc-libs-32bit: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-devel-32bit: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-client-32bit: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-client-32bit-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-libs-32bit-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-libs-python3-32bit: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-ad-dc-libs-32bit-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-libs-python3-32bit-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

libsamba-policy0-python3-32bit-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-client-libs-32bit-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

libsamba-policy0-python3-32bit: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-winbind-libs-32bit-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-libs-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-client-libs-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-debugsource: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-libs-python3-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-client: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

ctdb: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-winbind: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

libsamba-policy-devel: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-test: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-python3-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-winbind-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-dsdb-modules: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-winbind-libs-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

ctdb-pcp-pmda-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-devel: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

ctdb-pcp-pmda: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-libs-python3: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-libs: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

libsamba-policy-python3-devel: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

libsamba-policy0-python3: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-dsdb-modules-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

ctdb-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-ldb-ldap: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-test-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-ad-dc: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-winbind-libs: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-gpupdate: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-ldb-ldap-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-client-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-tool: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-ad-dc-libs-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

libsamba-policy0-python3-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-python3: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-client-libs: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-ad-dc-libs: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-ad-dc-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

External links

http://www.suse.com/support/update/announcement/2023/suse-su-20234059-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

2) Information disclosure

EUVDB-ID: #VU81874

Risk: Medium

CVSSv3.1: 5.9 [CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2023-4154

CWE-ID: CWE-200 - Information exposure

Exploit availability: No

Description

The vulnerability allows a remote user to gain access to potentially sensitive information.

The vulnerability exists due to a design error in Samba's implementation of the DirSync control, which can allow replication of critical domain passwords and secrets by Active Directory accounts authorized to do some replication, but not to replicate sensitive attributes. A remote user can obtain sensitive information from the AD DC and compromise the Active Directory.

Mitigation

Update the affected package samba to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Micro for Rancher: 5.3 - 5.4

SUSE Linux Enterprise High Availability Extension 15: SP4

SUSE Linux Enterprise Micro: 5.3 - 5.4

SUSE Linux Enterprise Server for SAP Applications 15: SP4

SUSE Linux Enterprise Server 15: SP4

SUSE Linux Enterprise Real Time 15: SP4

SUSE Linux Enterprise High Performance Computing 15: SP4

SUSE Linux Enterprise Desktop 15: SP4

Basesystem Module: 15-SP4

SUSE Manager Retail Branch Server: 4.3

SUSE Manager Server: 4.3

SUSE Manager Proxy: 4.3

openSUSE Leap: 15.4

samba-libs-64bit: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-client-64bit: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-client-libs-64bit-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-ad-dc-libs-64bit: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-libs-python3-64bit: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-winbind-libs-64bit: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-libs-python3-64bit-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-client-64bit-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-client-libs-64bit: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-devel-64bit: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-winbind-libs-64bit-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-libs-64bit-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-ad-dc-libs-64bit-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

libsamba-policy0-python3-64bit: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

libsamba-policy0-python3-64bit-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-ceph-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-ceph: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-doc: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-winbind-libs-32bit: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-client-libs-32bit: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-libs-32bit: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-ad-dc-libs-32bit: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-devel-32bit: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-client-32bit: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-client-32bit-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-libs-32bit-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-libs-python3-32bit: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-ad-dc-libs-32bit-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-libs-python3-32bit-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

libsamba-policy0-python3-32bit-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-client-libs-32bit-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

libsamba-policy0-python3-32bit: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-winbind-libs-32bit-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-libs-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-client-libs-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-debugsource: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-libs-python3-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-client: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

ctdb: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-winbind: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

libsamba-policy-devel: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-test: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-python3-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-winbind-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-dsdb-modules: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-winbind-libs-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

ctdb-pcp-pmda-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-devel: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

ctdb-pcp-pmda: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-libs-python3: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-libs: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

libsamba-policy-python3-devel: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

libsamba-policy0-python3: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-dsdb-modules-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

ctdb-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-ldb-ldap: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-test-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-ad-dc: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-winbind-libs: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-gpupdate: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-ldb-ldap-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-client-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-tool: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-ad-dc-libs-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

libsamba-policy0-python3-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-python3: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-client-libs: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-ad-dc-libs: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-ad-dc-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

External links

http://www.suse.com/support/update/announcement/2023/suse-su-20234059-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated privileged user via the local network (LAN).

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

3) Resource management error

EUVDB-ID: #VU81871

Risk: Medium

CVSSv3.1: 5.7 [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2023-42669

CWE-ID: CWE-399 - Resource Management Errors

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to inclusion of the "rpcecho" server into production build, which can call sleep() on AD DC. A remote user can request the server block using the "rpcecho" server and perform a denial of service (DoS) attack.

Mitigation

Update the affected package samba to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Micro for Rancher: 5.3 - 5.4

SUSE Linux Enterprise High Availability Extension 15: SP4

SUSE Linux Enterprise Micro: 5.3 - 5.4

SUSE Linux Enterprise Server for SAP Applications 15: SP4

SUSE Linux Enterprise Server 15: SP4

SUSE Linux Enterprise Real Time 15: SP4

SUSE Linux Enterprise High Performance Computing 15: SP4

SUSE Linux Enterprise Desktop 15: SP4

Basesystem Module: 15-SP4

SUSE Manager Retail Branch Server: 4.3

SUSE Manager Server: 4.3

SUSE Manager Proxy: 4.3

openSUSE Leap: 15.4

samba-libs-64bit: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-client-64bit: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-client-libs-64bit-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-ad-dc-libs-64bit: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-libs-python3-64bit: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-winbind-libs-64bit: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-libs-python3-64bit-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-client-64bit-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-client-libs-64bit: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-devel-64bit: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-winbind-libs-64bit-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-libs-64bit-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-ad-dc-libs-64bit-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

libsamba-policy0-python3-64bit: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

libsamba-policy0-python3-64bit-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-ceph-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-ceph: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-doc: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-winbind-libs-32bit: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-client-libs-32bit: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-libs-32bit: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-ad-dc-libs-32bit: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-devel-32bit: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-client-32bit: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-client-32bit-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-libs-32bit-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-libs-python3-32bit: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-ad-dc-libs-32bit-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-libs-python3-32bit-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

libsamba-policy0-python3-32bit-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-client-libs-32bit-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

libsamba-policy0-python3-32bit: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-winbind-libs-32bit-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-libs-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-client-libs-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-debugsource: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-libs-python3-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-client: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

ctdb: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-winbind: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

libsamba-policy-devel: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-test: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-python3-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-winbind-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-dsdb-modules: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-winbind-libs-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

ctdb-pcp-pmda-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-devel: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

ctdb-pcp-pmda: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-libs-python3: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-libs: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

libsamba-policy-python3-devel: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

libsamba-policy0-python3: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-dsdb-modules-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

ctdb-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-ldb-ldap: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-test-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-ad-dc: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-winbind-libs: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-gpupdate: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-ldb-ldap-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-client-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-tool: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-ad-dc-libs-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

libsamba-policy0-python3-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-python3: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-client-libs: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-ad-dc-libs: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

samba-ad-dc-debuginfo: before 4.15.13+git.691.3d3cea0641-150400.3.31.1

External links

http://www.suse.com/support/update/announcement/2023/suse-su-20234059-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###