Heap-based Buffer Overflow in Samba GSSAPI by Heimdal
CVE-2022-3437
6.5MEDIUM
What is CVE-2022-3437?
A heap-based buffer overflow vulnerability exists in Samba's GSSAPI routines, specifically in the unwrap_des() and unwrap_des3() functions of the Heimdal library. This flaw is triggered when the application processes a maliciously crafted small packet, allowing a remote attacker to exploit memory allocated by malloc(). The compromise could lead to potential denial of service (DoS) conditions, impacting the availability and integrity of the affected system.
Affected Version(s)
samba Fixed in samba 4.15.11, samba 4.16.6, samba 4.17.2.