跳转到帖子

Debian: CVE-2023-42669: samba -- security update

recommended_posts

发布于
  • Members

Debian: CVE-2023-42669: samba -- security update

Severity
7
CVSS
(AV:N/AC:L/Au:S/C:N/I:N/A:C)
Published
10/19/2023
Created
10/20/2023
Added
10/19/2023
Modified
01/30/2025

Description

A vulnerability was found in Samba's "rpcecho" development server, a non-Windows RPC server used to test Samba's DCE/RPC stack elements. This vulnerability stems from an RPC function that can be blocked indefinitely. The issue arises because the "rpcecho" service operates with only one worker in the main RPC task, allowing calls to the "rpcecho" server to be blocked for a specified time, causing service disruptions. This disruption is triggered by a "sleep()" call in the "dcesrv_echo_TestSleep()" function under specific conditions. Authenticated users or attackers can exploit this vulnerability to make calls to the "rpcecho" server, requesting it to block for a specified duration, effectively disrupting most services and leading to a complete denial of service on the AD DC. The DoS affects all other services as "rpcecho" runs in the main RPC task.

Solution(s)

  • debian-upgrade-samba

References

  • https://attackerkb.com/topics/cve-2023-42669
  • CVE - 2023-42669
  • DSA-5525-1
  • 查看数 703
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。
注意:你的帖子需要版主批准后才能看到。

游客
回帖…