FlawAtlas
Search the atlas
SUSE-SU-2023:1687-1 Not scored

Security update for ldb, samba

This update for ldb, samba fixes the following issues: ldb: - CVE-2022-32746: Fixed an use-after-free issue in the database audit logging module (bsc#1201490). - CVE-2023-0614: Fixed discovering of access controlled AD LDAP attributes (bso#15270) (bsc#1209485). samba: - CVE-2023-0922: Fixed cleartext password sending by AD DC admin tool (bso#15315) (bsc#1209481). - CVE-2023-0225: Fixed deletion of AD DC 'dnsHostname' attribute by unprivileged authenticated users (bso#15276) (bsc#1209483). - CVE-2023-0614: Fixed discovering of access controlled AD LDAP attributes (bso#15270) (bsc#1209485). The following non-security bug was fixed: - Prevent use after free of messaging_ctdb_fde_ev structs (bso#15293) (bsc#1207416).

Exploit probability Not scored
Published March 29, 2023
Required by Not available
Last source change May 2, 2025

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Enterprise Storage 7.1 ldb
SUSE:Enterprise Storage 7.1 samba
SUSE:Linux Enterprise High Availability Extension 15 SP3 samba
SUSE:Linux Enterprise High Performance Computing 15 SP3-ESPOS ldb
SUSE:Linux Enterprise High Performance Computing 15 SP3-ESPOS samba
SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS ldb
SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS samba
SUSE:Linux Enterprise Micro 5.1 ldb
SUSE:Linux Enterprise Micro 5.2 ldb
SUSE:Linux Enterprise Micro 5.2 samba
SUSE:Linux Enterprise Real Time 15 SP3 ldb
SUSE:Linux Enterprise Real Time 15 SP3 samba
SUSE:Linux Enterprise Server 15 SP3-LTSS ldb
SUSE:Linux Enterprise Server 15 SP3-LTSS samba
SUSE:Linux Enterprise Server for SAP Applications 15 SP3 ldb
SUSE:Linux Enterprise Server for SAP Applications 15 SP3 samba
SUSE:Manager Proxy 4.2 ldb
SUSE:Manager Proxy 4.2 samba
SUSE:Manager Server 4.2 ldb
SUSE:Manager Server 4.2 samba

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2023:1687-1

This update for ldb, samba fixes the following issues: ldb: - CVE-2022-32746: Fixed an use-after-free issue in the database audit logging module (bsc#1201490). - CVE-2023-0614: Fixed discovering of access controlled AD LDAP attributes (bso#15270) (bsc#1209485). samba: - CVE-2023-0922: Fixed cleartext password sending by AD DC admin tool (bso#15315) (bsc#1209481). - CVE-2023-0225: Fixed deletion of AD DC 'dnsHostname' attribute by unprivileged authenticated users (bso#15276) (bsc#1209483). - CVE-2023-0614: Fixed discovering of access controlled AD LDAP attributes (bso#15270) (bsc#1209485). The following non-security bug was fixed: - Prevent use after free of messaging_ctdb_fde_ev structs (bso#15293) (bsc#1207416).

View original source

05 / REFERENCES

Further evidence