Samba Security Updates – 16 October 2023

Samba has released security updates to address vulnerabilities affecting multiple Samba versions.

The addressed vulnerabilities could allow the attacker to bypass security restrictions, obtain sensitive information, or perform denial of service attacks on the affected system by sending a specially crafted request.

Sample of the addressed vulnerabilities:

1. Samba Information Disclosure Vulnerability (CVE-2023-4154):

  • CVSS: 7.5
  • Attack Vector: Network
  • Attack Complexity: High
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Obtain Information

2. Samba Security Bypass Vulnerability (CVE-2023-3961):

  • CVSS: 6.8
  • Attack Vector: Network
  • Attack Complexity: High
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Bypass Security
Vulnerabilities
  • CVE-2023-4091
  • CVE-2023-4154
  • CVE-2023-3961
  • CVE-2023-42669
  • CVE-2023-42670
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Samba Security Advisory

References