Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-42898
HistoryDec 25, 2022 - 12:00 a.m.

CVE-2022-42898

2022-12-2500:00:00
ubuntu.com
ubuntu.com
45
cve-2022-42898
pac parsing
integer overflows
remote code execution
kdc
kadmind
gss
denial of service
heimdal
samba
heap-based buffer overflow

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.007

Percentile

80.5%

PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before
1.20.1 has integer overflows that may lead to remote code execution (in
KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms
(which have a resultant heap-based buffer overflow), and cause a denial of
service on other platforms. This occurs in krb5_pac_parse in
lib/krb5/krb/pac.c. Heimdal before 7.7.1 has “a similar bug.”

Bugs

Notes

Author Note
mdeslaur Per upstream Samba advisory, this is only an issue on 32-bit systems.
rodrigo-zaiden a regression in heimdal was reported by samba and fixed in https://github.com/heimdal/heimdal/pull/1025
mdeslaur See samba bug for samba regression fix not yet commited The focal samba update was temporarily reverted by USN 5822-2 because it introduced regressions. It was later updated again with USN 5936-1.
OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchheimdal< 7.5.0+dfsg-1ubuntu0.3UNKNOWN
ubuntu20.04noarchheimdal< 7.7.0+dfsg-1ubuntu1.3UNKNOWN
ubuntu22.04noarchheimdal< anyUNKNOWN
ubuntu24.04noarchheimdal< anyUNKNOWN
ubuntu14.04noarchheimdal< 1.6~git20131207+dfsg-1ubuntu1.2+esm3UNKNOWN
ubuntu16.04noarchheimdal< 1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm3UNKNOWN
ubuntu18.04noarchkrb5< 1.16-2ubuntu0.3UNKNOWN
ubuntu20.04noarchkrb5< 1.17-6ubuntu4.2UNKNOWN
ubuntu22.04noarchkrb5< 1.19.2-2ubuntu0.1UNKNOWN
ubuntu22.10noarchkrb5< 1.20-1ubuntu0.1UNKNOWN
Rows per page:
1-10 of 181

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.007

Percentile

80.5%