Lucene search

K
altlinuxHttps://packages.altlinux.org/en/sisyphus/security/BF52E75014C50AA702D1558FA5C40CD6
HistoryNov 22, 2022 - 12:00 a.m.

Security fix for the ALT Linux 10 package samba version 4.16.7-alt1

2022-11-2200:00:00
https://packages.altlinux.org/en/sisyphus/security/
packages.altlinux.org
12
samba 4.16
security fix
cve-2022-42898
integer overflows
32-bit system
ad dc
file servers
non-ad domain

0.005 Low

EPSS

Percentile

76.3%

Nov. 22, 2022 Evgeny Sinelnikov 4.16.7-alt1

- Update to maintenance release of Samba 4.16 (Samba#15203)
- Security fixes:
  + CVE-2022-42898: Samba's Kerberos libraries and AD DC failed to guard against
                    integer overflows when parsing a PAC on a 32-bit system, which
                    allowed an attacker with a forged PAC to corrupt the heap.
                    https://www.samba.org/samba/security/CVE-2022-42898.html
    Workaround and mitigations:
    * No workaround on 32-bit systems as an AD DC
    * file servers are only impacted if in a non-AD domain
    * 64-bit systems are not exploitable