CVE-2023-0614
03.04.2023, 23:15
The fix in 4.6.16, 4.7.9, 4.8.4 and 4.9.7 for CVE-2018-10919 Confidential attribute disclosure vi LDAP filters was insufficient and an attacker may be able to obtain confidential BitLocker recovery keys from a Samba AD DC.Enginsight
Vendor | Product | Version |
---|---|---|
samba | samba | 4.0.0 ≤ 𝑥 < 4.16.10 |
samba | samba | 4.17.0 ≤ 𝑥 < 4.17.7 |
samba | samba | 4.18.0 |
samba | samba | 4.18.0:rc1 |
samba | samba | 4.18.0:rc2 |
samba | samba | 4.18.0:rc3 |
samba | samba | 4.18.0:rc4 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
ldb |
| ||||||||||||||||||||
samba |
|
Common Weakness Enumeration
- CWE-200 - Exposure of Sensitive Information to an Unauthorized ActorThe product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
- CWE-312 - Cleartext Storage of Sensitive InformationThe product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
References