FlawAtlas
Search the atlas
SUSE-SU-2023:1689-1 Not scored

Security update for ldb, samba

This update for ldb, samba fixes the following issues: ldb: - CVE-2022-32746: Fixed an use-after-free issue in the database audit logging module (bsc#1201490). - CVE-2023-0614: Fixed discovering of access controlled AD LDAP attributes (bso#15270) (bsc#1209485). samba: - CVE-2023-0922: Fixed cleartext password sending by AD DC admin tool (bso#15315) (bsc#1209481). - CVE-2023-0225: Fixed deletion of AD DC 'dnsHostname' attribute by unprivileged authenticated users (bso#15276) (bsc#1209483). - CVE-2023-0614: Fixed discovering of access controlled AD LDAP attributes (bso#15270) (bsc#1209485). The following non-security bug were fixed: - Prevent use after free of messaging_ctdb_fde_ev structs (bso#15293) (bsc#1207416). - Ship missing samba-winbind-libs-32bit package (bsc#1207996) - Ship missing samba-libs to SLE Micro 5.3 (bsc#1207723)

Exploit probability Not scored
Published March 29, 2023
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise High Availability Extension 15 SP4 samba
SUSE:Linux Enterprise Micro 5.3 ldb
SUSE:Linux Enterprise Micro 5.3 samba
SUSE:Linux Enterprise Micro 5.4 ldb
SUSE:Linux Enterprise Micro 5.4 samba
SUSE:Linux Enterprise Module for Basesystem 15 SP4 ldb
SUSE:Linux Enterprise Module for Basesystem 15 SP4 samba
openSUSE:Leap 15.4 ldb
openSUSE:Leap 15.4 samba
openSUSE:Leap Micro 5.3 ldb
openSUSE:Leap Micro 5.3 samba

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2023:1689-1

This update for ldb, samba fixes the following issues: ldb: - CVE-2022-32746: Fixed an use-after-free issue in the database audit logging module (bsc#1201490). - CVE-2023-0614: Fixed discovering of access controlled AD LDAP attributes (bso#15270) (bsc#1209485). samba: - CVE-2023-0922: Fixed cleartext password sending by AD DC admin tool (bso#15315) (bsc#1209481). - CVE-2023-0225: Fixed deletion of AD DC 'dnsHostname' attribute by unprivileged authenticated users (bso#15276) (bsc#1209483). - CVE-2023-0614: Fixed discovering of access controlled AD LDAP attributes (bso#15270) (bsc#1209485). The following non-security bug were fixed: - Prevent use after free of messaging_ctdb_fde_ev structs (bso#15293) (bsc#1207416). - Ship missing samba-winbind-libs-32bit package (bsc#1207996) - Ship missing samba-libs to SLE Micro 5.3 (bsc#1207723)

View original source

05 / REFERENCES

Further evidence