CVE-2023-42670
Samba: ad dc busy rpc multiple listener dos
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A flaw was found in Samba. It is susceptible to a vulnerability where multiple incompatible RPC listeners can be initiated, causing disruptions in the AD DC service. When Samba's RPC server experiences a high load or unresponsiveness, servers intended for non-AD DC purposes (for example, NT4-emulation "classic DCs") can erroneously start and compete for the same unix domain sockets. This issue leads to partial query responses from the AD DC, causing issues such as "The procedure number is out of range" when using tools like Active Directory Users. This flaw allows an attacker to disrupt AD DC services.
Se encontró una falla en Samba. Es susceptible a una vulnerabilidad en la que se pueden iniciar múltiples escuchas RPC incompatibles, lo que provoca interrupciones en el servicio AD DC. Cuando el servidor RPC de Samba experimenta una carga alta o no responde, los servidores destinados a fines que no son AD DC (por ejemplo, los "DC clásicos" de NT4-emulation) pueden iniciarse erróneamente y competir por los mismos sockets de dominio Unix. Este problema genera respuestas de consulta parciales del AD DC, lo que provoca problemas como "El número de procedimiento está fuera de rango" cuando se utilizan herramientas como Usuarios de Active Directory. Esta falla permite a un atacante interrumpir los servicios de AD DC.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2023-09-13 CVE Reserved
- 2023-10-11 CVE Published
- 2024-11-06 CVE Updated
- 2024-11-09 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-400: Uncontrolled Resource Consumption
CAPEC
References (6)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.samba.org/samba/security/CVE-2023-42670.html | 2023-11-24 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | < 4.17.12 Search vendor "Samba" for product "Samba" and version " < 4.17.12" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | >= 4.18.0 < 4.18.8 Search vendor "Samba" for product "Samba" and version " >= 4.18.0 < 4.18.8" | - |
Affected
| ||||||
Samba Search vendor "Samba" | Samba Search vendor "Samba" for product "Samba" | >= 4.19.0 < 4.19.1 Search vendor "Samba" for product "Samba" and version " >= 4.19.0 < 4.19.1" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 39 Search vendor "Fedoraproject" for product "Fedora" and version "39" | - |
Affected
|