CVE Database
/

CVE-2022-3437

Back to search

CVE-2022-3437

Published: Jan 12, 2023

Modified: Oct 28, 2024

PUBLISHED

Description

A heap-based buffer overflow vulnerability was found in Samba within the GSSAPI unwrap_des() and unwrap_des3() routines of Heimdal. The DES and Triple-DES decryption routines in the Heimdal GSSAPI library allow a length-limited write buffer overflow on malloc() allocated memory when presented with a maliciously small packet. This flaw allows a remote user to send specially crafted malicious data to the application, possibly resulting in a denial of service (DoS) attack.

VendorProductVersions

n/a

samba

affected
Fixed in samba 4.15.11, samba 4.16.6, samba 4.17.2.

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now