CVE-2022-3437

CVSS V2 None CVSS V3 None
Description
A heap-based buffer overflow vulnerability was found in Samba within the GSSAPI unwrap_des() and unwrap_des3() routines of Heimdal. The DES and Triple-DES decryption routines in the Heimdal GSSAPI library allow a length-limited write buffer overflow on malloc() allocated memory when presented with a maliciously small packet. This flaw allows a remote user to send specially crafted malicious data to the application, possibly resulting in a denial of service (DoS) attack.
Overview
  • CVE ID
  • CVE-2022-3437
  • Assigner
  • secalert@redhat.com
  • Vulnerability Status
  • Modified
  • Published Version
  • 2023-01-12T15:15:10
  • Last Modified Date
  • 2023-02-16T14:15:16
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* 1 OR 4.0.0 4.15.11
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* 1 OR 4.16.0 4.16.6
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* 1 OR 4.17.0 4.17.2
cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* 1 OR
History
Created Old Value New Value Data Type Notes
2023-01-12 15:15:54 Added to TrackCVE
2023-01-12 15:15:55 Weakness Enumeration new
2023-01-12 20:16:08 2023-01-12T19:20:24 CVE Modified Date updated
2023-01-12 20:16:08 Received Awaiting Analysis Vulnerability Status updated
2023-01-18 19:18:53 Awaiting Analysis Undergoing Analysis Vulnerability Status updated
2023-01-20 08:14:02 2023-01-20T08:01:56 CVE Modified Date updated
2023-01-20 08:14:02 Undergoing Analysis Analyzed Vulnerability Status updated
2023-01-20 08:14:04 CPE Information updated
2023-02-08 11:14:58 2023-02-08T10:15:09 CVE Modified Date updated
2023-02-08 11:14:58 Analyzed Modified Vulnerability Status updated
2023-02-08 11:14:59 References updated
2023-02-16 15:13:51 2023-02-16T14:15:16 CVE Modified Date updated
2023-02-16 15:13:51 References updated