PT-2023-6230 · Samba+5 · Samba+5
Kirin Van Der Veer
·
Published
2023-10-10
·
Updated
2024-11-15
·
CVE-2023-42670
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Samba (affected versions not specified)
Description
A flaw was found in Samba, making it susceptible to a vulnerability where multiple incompatible RPC listeners can be initiated, causing disruptions in the AD DC service. When Samba's RPC server experiences a high load or unresponsiveness, servers intended for non-AD DC purposes can erroneously start and compete for the same unix domain sockets, leading to partial query responses from the AD DC. This issue can cause problems such as "The procedure number is out of range" when using tools like Active Directory Users. The vulnerability is related to incorrect resource release in the RPC server, allowing a remote attacker to disrupt AD DC services by exploiting this flaw.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Improper Resource Release
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Linuxmint
Red Os
Samba
Suse
Ubuntu