Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-34967
HistoryJul 19, 2023 - 12:00 a.m.

CVE-2023-34967

2023-07-1900:00:00
ubuntu.com
ubuntu.com
13
samba
rpc service
type confusion
spotlight
vulnerability
ubuntu
bug
mdssvc worker process
crash

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

0.041 Low

EPSS

Percentile

92.2%

A Type Confusion vulnerability was found in Samba’s mdssvc RPC service for
Spotlight. When parsing Spotlight mdssvc RPC packets, one encoded data
structure is a key-value style dictionary where the keys are character
strings, and the values can be any of the supported types in the mdssvc
protocol. Due to a lack of type checking in callers of the
dalloc_value_for_key() function, which returns the object associated with a
key, a caller may trigger a crash in talloc_get_size() when talloc detects
that the passed-in pointer is not a valid talloc pointer. With an RPC
worker process shared among multiple client connections, a malicious client
or attacker can trigger a process crash in a shared RPC mdssvc worker
process, affecting all other clients this worker serves.

Bugs

Notes

Author Note
sbeattie Spotlight functionality first enabled in 4.13.x in Ubuntu (so focal), in older releases the Spotlight service is not built.
OSVersionArchitecturePackageVersionFilename
ubuntu20.04noarchsamba< 2:4.15.13+dfsg-0ubuntu0.20.04.3UNKNOWN
ubuntu22.04noarchsamba< 2:4.15.13+dfsg-0ubuntu1.2UNKNOWN
ubuntu22.10noarchsamba< 2:4.16.8+dfsg-0ubuntu1.2UNKNOWN
ubuntu23.04noarchsamba< 2:4.17.7+dfsg-1ubuntu1.1UNKNOWN
ubuntu23.10noarchsamba< 2:4.18.5+dfsg-1ubuntu1UNKNOWN

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

0.041 Low

EPSS

Percentile

92.2%