CVE-2023-34968
published 2023-07-20CVE-2023-34968: A path disclosure vulnerability was found in Samba. As part of the Spotlight protocol, Samba discloses the server-side absolute path of shares, files, and…
medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
A path disclosure vulnerability was found in Samba. As part of the Spotlight protocol, Samba discloses the server-side absolute path of shares, files, and directories in the results for search queries. This flaw allows a malicious client or an attacker with a targeted RPC request to view the information that is part of the disclosed path.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | samba | < samba 2:4.17.10+dfsg-0+deb12u1 (bookworm) | samba 2:4.17.10+dfsg-0+deb12u1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | storage | — | — |
| samba | samba | < 4.16.11 | 4.16.11 |
| samba | samba | >= 0 < 2:4.13.13+dfsg-1~deb11u6 | 2:4.13.13+dfsg-1~deb11u6 |
| samba | samba | >= 0 < 2:4.17.10+dfsg-0+deb12u1 | 2:4.17.10+dfsg-0+deb12u1 |
| samba | samba | >= 0 < 2:4.18.5+dfsg-1 | 2:4.18.5+dfsg-1 |
| samba | samba | >= 0 < 2:4.18.5+dfsg-1 | 2:4.18.5+dfsg-1 |
| samba | samba | >= 0 < 2:4.15.13+dfsg-0ubuntu0.20.04.3 | 2:4.15.13+dfsg-0ubuntu0.20.04.3 |
| samba | samba | >= 0 < 2:4.15.13+dfsg-0ubuntu1.2 | 2:4.15.13+dfsg-0ubuntu1.2 |
| samba | samba | >= 4.17.0 < 4.17.10 | 4.17.10 |
| samba | samba | >= 4.18.0 < 4.18.5 | 4.18.5 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
osv5.9MEDIUM