4.3
CVSSv3

CVE-2022-32742

Published: 25/08/2022 Updated: 22/04/2024
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

This vulnerability allows remote malicious users to disclose sensitive information on affected installations of Samba. Authentication is required to exploit this vulnerability, and SMB1 must be enabled on the target. The specific flaw exists within the Samba service, which listens on TCP port 139 by default. A crafted SMB1 command can trigger a read past the end of an allocated buffer. An attacker can leverage this vulnerability to disclose information in the context of the Samba service process or to create a denial-of-service condition on the system.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

samba samba

Vendor Advisories

Debian Bug report logs - #1016449 samba: CVE-2022-2031 CVE-2022-32742 CVE-2022-32744 CVE-2022-32745 CVE-2022-32746 Package: src:samba; Maintainer for src:samba is Debian Samba Maintainers <pkg-samba-maint@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 31 Jul 2022 19:42:02 UT ...
Several security issues were fixed in Samba ...
Several vulnerabilities have been discovered in Samba, a SMB/CIFS file, print, and login server for Unix CVE-2022-2031 Luke Howard reported that Samba AD users can bypass certain restrictions associated with changing passwords A user who has been requested to change their password can exploit this to obtain and use tickets to oth ...
Synopsis Important: OpenShift Container Platform 41112 security update Type/Severity Security Advisory: Important Topic Red Hat OpenShift Container Platform release 41112 is now available with updates to packages and images that fix several bugs and add enhancementsRed Hat Product Security has rated this update as having a security impac ...
Synopsis Moderate: samba security and bug fix update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for samba is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as hav ...
Synopsis Moderate: samba security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for samba is now available for Red Hat Enterprise Linux 9Red Hat Product Security has rated this ...
Synopsis Moderate: samba security, bug fix and enhancement update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic Updated samba packages that fix several bugs with added enhancements are now available for Red Hat Gluster S ...
A flaw was found in Samba Some SMB1 write requests were not correctly range-checked to ensure the client had sent enough data to fulfill the write, allowing server memory contents to be written into the file (or printer) instead of client-supplied data The client cannot control the area of the server memory written to the file (or printer) (CVE- ...
It was found that the Kerberos Key Distribution Center (KDC) delegation feature, Service for User (S4U), did not sufficiently protect the tickets it's providing from tempering A malicious, authenticated service principal allowed to delegate could use this flaw to impersonate a non-forwardable user (CVE-2020-17049) A flaw was found in Samba Some ...
A flaw was found in Samba Some SMB1 write requests were not correctly range-checked to ensure the client had sent enough data to fulfill the write, allowing server memory contents to be written into the file (or printer) instead of client-supplied data The client cannot control the area of the server memory written to the file (or printer) ...
Severity Unknown Remote Unknown Type Unknown Description AVG-2782 samba 4163-1 4164-1 Unknown Fixed ...
ALAS-2022-213 Amazon Linux 2022 Security Advisory: ALAS-2022-213 Advisory Release Date: 2022-12-06 16:41 Pacific ...