PT-2023-6230 · Samba+5 · Samba+5

Kirin Van Der Veer

·

Published

2023-10-10

·

Updated

2024-11-15

·

CVE-2023-42670

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Samba (affected versions not specified)
Description A flaw was found in Samba, making it susceptible to a vulnerability where multiple incompatible RPC listeners can be initiated, causing disruptions in the AD DC service. When Samba's RPC server experiences a high load or unresponsiveness, servers intended for non-AD DC purposes can erroneously start and compete for the same unix domain sockets, leading to partial query responses from the AD DC. This issue can cause problems such as "The procedure number is out of range" when using tools like Active Directory Users. The vulnerability is related to incorrect resource release in the RPC server, allowing a remote attacker to disrupt AD DC services by exploiting this flaw.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Improper Resource Release

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2023-6448
ALT-PU-2023-7794
ALT-PU-2024-12484
ALT-PU-2024-14683
AZL-31901
AZL-37028
BDU:2023-06939
CVE-2023-42670
DSA-5525-1
ECHO-9E4D-E76A-7140
OESA-2023-1756
OESA-2023-1757
OPENSUSE-SU-2023_4046-1
OPENSUSE-SU-2024:13332-1
SUSE-SU-2023:4046-1
USN-6425-1
USN-6425-2
USN-6425-3

Affected Products

Alt Linux
Linuxmint
Red Os
Samba
Suse
Ubuntu