PT-2023-7993 · Samba+9 · Samba+9
Arnaud Gatignol
+1
·
Published
2023-07-17
·
Updated
2024-11-15
·
CVE-2023-34967
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Samba (affected versions not specified)
Description
A Type Confusion vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing Spotlight mdssvc RPC packets, one encoded data structure is a key-value style dictionary where the keys are character strings, and the values can be any of the supported types in the mdssvc protocol. Due to a lack of type checking in callers of the
dalloc value for key() function, which returns the object associated with a key, a caller may trigger a crash in talloc get size() when talloc detects that the passed-in pointer is not a valid talloc pointer. With an RPC worker process shared among multiple client connections, a malicious client or attacker can trigger a process crash in a shared RPC mdssvc worker process, affecting all other clients this worker serves.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Type Confusion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Red Hat
Red Os
Samba
Suse
Ubuntu