Heap-based Buffer Overflow in Samba GSSAPI by Heimdal
CVE-2022-3437

6.5MEDIUM

Key Information:

Vendor

Samba

Status
Vendor
CVE Published:
12 January 2023

What is CVE-2022-3437?

A heap-based buffer overflow vulnerability exists in Samba's GSSAPI routines, specifically in the unwrap_des() and unwrap_des3() functions of the Heimdal library. This flaw is triggered when the application processes a maliciously crafted small packet, allowing a remote attacker to exploit memory allocated by malloc(). The compromise could lead to potential denial of service (DoS) conditions, impacting the availability and integrity of the affected system.

Affected Version(s)

samba Fixed in samba 4.15.11, samba 4.16.6, samba 4.17.2.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2022-3437 : Heap-based Buffer Overflow in Samba GSSAPI by Heimdal