A path disclosure vulnerability was found in Samba. As part of the Spotlight protocol, Samba discloses the server-side absolute path of shares, files, and directories in the results for search queries. This flaw allows a malicious client or an attacker with a targeted RPC request to view the information that is part of the disclosed path.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
DSA-5477-1 | samba security update |
![]() |
DSA-5647-1 | samba security update |
![]() |
EUVD-2023-39007 | A path disclosure vulnerability was found in Samba. As part of the Spotlight protocol, Samba discloses the server-side absolute path of shares, files, and directories in the results for search queries. This flaw allows a malicious client or an attacker with a targeted RPC request to view the information that is part of the disclosed path. |
![]() |
USN-6238-1 | Samba vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 06 Dec 2024 11:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-201 |
Fri, 22 Nov 2024 12:00:00 +0000
Mon, 16 Sep 2024 13:30:00 +0000

Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-10-09T23:34:59.623Z
Reserved: 2023-06-07T21:11:04.262Z
Link: CVE-2023-34968

No data.

Status : Modified
Published: 2023-07-20T15:15:11.540
Modified: 2024-12-06T11:15:05.270
Link: CVE-2023-34968


No data.