Logo
vulnerabilityCVE-2023-34968
Name
CVE-2023-34968
Source
NVD ( link)Debian ( link)
Description
A path disclosure vulnerability was found in Samba. As part of the Spotlight protocol, Samba discloses the server-side absolute path of shares, files, and directories in the results for search queries. This flaw allows a malicious client or an attacker with a targeted RPC request to view the information that is part of the disclosed path.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
samba
Patched

Vulnerability Ratings#


5.3
CVSSv31
5.3
CVSSv31

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
4.22.10
Not Affected
buildroot
master
4.24.3
Not Affected
openwrt
master
4.22.7-r3
Not Affected
openwrt
openwrt-25.12
4.22.7-r3
Not Affected
yocto
master
4.23.5
Not Affected
yocto
scarthgap
4.19.9
Not Affected

Resolved with patches#


samba (yocto:kirkstone)

#
Title
Author
Resolve
1
CVE-2023-34968: mdssvc: add missing "kMDSStoreMetaScopes"
Ralph Boehme <slow@samba.org>
CVE-2023-34968
2
CVE-2023-34968: smbtorture: remove response blob allocation
Ralph Boehme <slow@samba.org>
CVE-2023-34968
3
CVE-2023-34968: mdssvc: remove response blob allocation
Ralph Boehme <slow@samba.org>
CVE-2023-34968
4
CVE-2023-34968: mdssvc: return a fake share path Instead of
Ralph Boehme <slow@samba.org>
CVE-2023-34968
5
CVE-2023-34968: mdscli: use correct TALLOC memory context
Ralph Boehme <slow@samba.org>
CVE-2023-34968
6
CVE-2023-34968: mdscli: return share relative paths The next
Ralph Boehme <slow@samba.org>
CVE-2023-34968
7
CVE-2023-34968: mdssvc: introduce an allocating wrapper to
Ralph Boehme <slow@samba.org>
CVE-2023-34968
8
CVE-2023-34968: mdssvc: cache and reuse stat info in struct
Ralph Boehme <slow@samba.org>
CVE-2023-34968
9
CVE-2023-34968: mdssvc: switch to doing an early return
Archana Polampalli <archana.polampalli@windriver.com>
CVE-2023-34968
10
CVE-2023-34968: rpcclient: remove response blob allocation
Ralph Boehme <slow@samba.org>
CVE-2023-34968