An information leak vulnerability was discovered in Samba's LDAP server. Due to missing access control checks, an authenticated but unprivileged attacker could discover the names and preserved attributes of deleted objects in the LDAP store.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://bugzilla.samba.org/show_bug.cgi?id=13595 | patch exploit vendor advisory issue tracking |
https://bugzilla.redhat.com/show_bug.cgi?id=1625445 | patch exploit third party advisory issue tracking |
http://www.openwall.com/lists/oss-security/2023/11/28/4 | mailing list |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6DK57HQRTCDOZDIIICYWQ4Z5IQXTWVVW/ | third party advisory patch |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ACVMYEP5KJRL3FWSCZW2MQZ26IVPXY62/ | third party advisory patch |
https://security.netapp.com/advisory/ntap-20230223-0008/ | third party advisory |