Search CVE reports


Toggle filters

11 – 20 of 188 results


CVE-2023-3347

Medium priority
Fixed

A vulnerability was found in Samba's SMB2 packet signing mechanism. The SMB2 packet signing is not enforced if an admin configured "server signing = required" or for SMB2 connections to Domain Controllers where SMB2 packet signing...

1 affected package

samba

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba Not affected Not affected Not affected
Show less packages

CVE-2023-0922

Medium priority

Some fixes available 8 of 11

The Samba AD DC administration tool, when operating against a remote LDAP server, will by default send new or reset passwords over a signed-only connection.

1 affected package

samba

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba Fixed Fixed Fixed Vulnerable
Show less packages

CVE-2023-0614

Medium priority

Some fixes available 10 of 16

The fix in 4.6.16, 4.7.9, 4.8.4 and 4.9.7 for CVE-2018-10919 Confidential attribute disclosure vi LDAP filters was insufficient and an attacker may be able to obtain confidential BitLocker recovery keys from a Samba AD DC.

2 affected packages

ldb, samba

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ldb Not in release Fixed Fixed Vulnerable
samba Fixed Fixed Fixed Vulnerable
Show less packages

CVE-2023-0225

Medium priority
Fixed

A flaw was found in Samba. An incomplete access check on dnsHostName allows authenticated but otherwise unprivileged users to delete this attribute from any object in the directory.

1 affected package

samba

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba Not affected Not affected Not affected
Show less packages

CVE-2022-45141

Medium priority
Fixed

Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was disclosed by Microsoft on Nov 8 2022 and per RFC8429 it is assumed that rc4-hmac is weak, Vulnerable Samba Active Directory DCs will issue...

1 affected package

samba

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba Not affected Fixed Fixed Fixed
Show less packages

CVE-2022-44640

Medium priority

Some fixes available 4 of 11

Heimdal before 7.7.1 allows remote attackers to execute arbitrary code because of an invalid free in the ASN.1 codec used by the Key Distribution Center (KDC).

2 affected packages

heimdal, samba

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
heimdal Vulnerable Vulnerable Fixed Fixed
samba Not affected Not affected Not affected Not affected
Show less packages

CVE-2022-42898

Medium priority

Some fixes available 16 of 23

PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which...

3 affected packages

heimdal, samba, krb5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
heimdal Vulnerable Vulnerable Fixed Fixed
samba Not affected Fixed Fixed Fixed
krb5 Not affected Fixed Fixed Fixed
Show less packages

CVE-2022-38023

Medium priority

Some fixes available 8 of 11

Netlogon RPC Elevation of Privilege Vulnerability

1 affected package

samba

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba Fixed Fixed Fixed Vulnerable
Show less packages

CVE-2022-37967

Medium priority

Some fixes available 8 of 11

Windows Kerberos Elevation of Privilege Vulnerability

1 affected package

samba

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba Fixed Fixed Fixed Vulnerable
Show less packages

CVE-2022-37966

Medium priority

Some fixes available 8 of 11

Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability

1 affected package

samba

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba Fixed Fixed Fixed Vulnerable
Show less packages