Lucene search

K
cvelistRedhatCVELIST:CVE-2022-32742
HistoryAug 25, 2022 - 12:00 a.m.

CVE-2022-32742

2022-08-2500:00:00
CWE-200
redhat
www.cve.org
13
samba
smb1
write requests
range-checked
server memory
client control

AI Score

6.8

Confidence

High

EPSS

0.043

Percentile

92.4%

A flaw was found in Samba. Some SMB1 write requests were not correctly range-checked to ensure the client had sent enough data to fulfill the write, allowing server memory contents to be written into the file (or printer) instead of client-supplied data. The client cannot control the area of the server memory written to the file (or printer).

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "samba",
    "versions": [
      {
        "version": "Versions prior to samba 4.16.4, samba 4.15.9, samba 4.14.14",
        "status": "affected"
      }
    ]
  }
]