CVE-2023-0225

CVSS V2 None CVSS V3 None
Description
A flaw was found in Samba. An incomplete access check on dnsHostName allows authenticated but otherwise unprivileged users to delete this attribute from any object in the directory.
Overview
  • CVE ID
  • CVE-2023-0225
  • Assigner
  • secalert@redhat.com
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2023-04-03T23:15:06
  • Last Modified Date
  • 2023-04-14T15:02:10
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* 1 OR 4.17.0 4.17.7
cpe:2.3:a:samba:samba:4.18.0:-:*:*:*:*:*:* 1 OR
cpe:2.3:a:samba:samba:4.18.0:rc1:*:*:*:*:*:* 1 OR
cpe:2.3:a:samba:samba:4.18.0:rc2:*:*:*:*:*:* 1 OR
cpe:2.3:a:samba:samba:4.18.0:rc3:*:*:*:*:*:* 1 OR
cpe:2.3:a:samba:samba:4.18.0:rc4:*:*:*:*:*:* 1 OR
References
Reference URL Reference Tags
https://security.netapp.com/advisory/ntap-20230406-0007/ Third Party Advisory
https://www.samba.org/samba/security/CVE-2023-0225.html Mitigation Vendor Advisory
History
Created Old Value New Value Data Type Notes
2023-04-17 04:03:39 Added to TrackCVE
2023-04-17 04:03:42 Weakness Enumeration new