5.4
CVSSv3

CVE-2022-32746

Published: 25/08/2022 Updated: 17/09/2023
CVSS v3 Base Score: 5.4 | Impact Score: 2.5 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

A flaw was found in the Samba AD LDAP server. The AD DC database audit logging module can access LDAP message values freed by a preceding database module, resulting in a use-after-free issue. This issue is only possible when modifying certain privileged attributes, such as userAccountControl.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

samba samba

Vendor Advisories

Synopsis Moderate: libldb security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for libldb is now available for Red Hat Enterprise Linux 9Red Hat Product Security has rated th ...
Debian Bug report logs - #1016449 samba: CVE-2022-2031 CVE-2022-32742 CVE-2022-32744 CVE-2022-32745 CVE-2022-32746 Package: src:samba; Maintainer for src:samba is Debian Samba Maintainers <pkg-samba-maint@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 31 Jul 2022 19:42:02 UT ...
Several security issues were fixed in Samba ...
Several vulnerabilities have been discovered in Samba, a SMB/CIFS file, print, and login server for Unix CVE-2022-2031 Luke Howard reported that Samba AD users can bypass certain restrictions associated with changing passwords A user who has been requested to change their password can exploit this to obtain and use tickets to oth ...
It was found that the Kerberos Key Distribution Center (KDC) delegation feature, Service for User (S4U), did not sufficiently protect the tickets it's providing from tempering A malicious, authenticated service principal allowed to delegate could use this flaw to impersonate a non-forwardable user (CVE-2020-17049) A flaw was found in Samba Some ...
A flaw was found in the Samba AD LDAP server The AD DC database audit logging module can access LDAP message values freed by a preceding database module, resulting in a use-after-free issue This issue is only possible when modifying certain privileged attributes, such as userAccountControl ...
Severity Unknown Remote Unknown Type Unknown Description AVG-2782 samba 4163-1 4164-1 Unknown Fixed ...
ALAS-2022-247 Amazon Linux 2022 Security Advisory: ALAS-2022-247 Advisory Release Date: 2022-12-06 16:44 Pacific ...
ALAS-2022-213 Amazon Linux 2022 Security Advisory: ALAS-2022-213 Advisory Release Date: 2022-12-06 16:41 Pacific ...