AI Score
Confidence
High
EPSS
Percentile
89.6%
SSVC
Exploitation
none
Automatable
no
Technical Impact
partial
A heap-based buffer overflow vulnerability was found in Samba within the GSSAPI unwrap_des() and unwrap_des3() routines of Heimdal. The DES and Triple-DES decryption routines in the Heimdal GSSAPI library allow a length-limited write buffer overflow on malloc() allocated memory when presented with a maliciously small packet. This flaw allows a remote user to send specially crafted malicious data to the application, possibly resulting in a denial of service (DoS) attack.
[
{
"cpes": [
"cpe:2.3:a:samba:samba:4.15.11:*:*:*:*:*:*:*"
],
"vendor": "samba",
"product": "samba",
"versions": [
{
"status": "unknown",
"version": "4.15.11"
}
],
"defaultStatus": "unknown"
}
]
www.openwall.com/lists/oss-security/2023/02/08/1
access.redhat.com/security/cve/CVE-2022-3437
bugzilla.redhat.com/show_bug.cgi?id=2137774
lists.debian.org/debian-lts-announce/2024/04/msg00015.html
security.gentoo.org/glsa/202309-06
security.gentoo.org/glsa/202310-06
security.netapp.com/advisory/ntap-20230216-0008/
www.samba.org/samba/security/CVE-2022-3437.html