Memory Disclosure Vulnerability in Samba Affects Multiple Platforms
CVE-2022-32742

4.3MEDIUM

Key Information:

Vendor

Samba

Status
Vendor
CVE Published:
25 August 2022

What is CVE-2022-32742?

A flaw exists in Samba where some SMB1 write requests lack sufficient range-checking, which enables server memory to potentially overwrite files or printer data. This vulnerability allows incorrect data to be written, as the client cannot dictate the memory area that is affected. Consequently, server memory contents may be unintentionally exposed or altered, posing significant security risks.

Affected Version(s)

samba Versions prior to samba 4.16.4, samba 4.15.9, samba 4.14.14

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.