UBUNTU-CVE-2022-3437
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-3437
UBUNTU-CVE-2022-3437
Summary:
Details: A heap-based buffer overflow vulnerability was found in Samba within the GSSAPI unwrap_des() and unwrap_des3() routines of Heimdal. The DES and Triple-DES decryption routines in the Heimdal GSSAPI library allow a length-limited write buffer overflow on malloc() allocated memory when presented with a maliciously small packet. This flaw allows a remote user to send specially crafted malicious data to the application, possibly resulting in a denial of service (DoS) attack.
References: https://ubuntu.com/security/CVE-2022-3437, https://www.samba.org/samba/security/CVE-2022-3437.html, https://github.com/heimdal/heimdal/security/advisories/GHSA-45j3-5v39-rf9j, https://ubuntu.com/security/notices/USN-5800-1, https://ubuntu.com/security/notices/USN-5822-1, https://ubuntu.com/security/notices/USN-5822-2, https://ubuntu.com/security/notices/USN-5936-1, https://www.cve.org/CVERecord?id=CVE-2022-3437, https://ubuntu.com/security/notices/USN-7582-1
Affected packages
Package
Name: heimdal
Purl: pkg:deb/ubuntu/[email protected]~git20131207+dfsg-1ubuntu1.2+esm3?arch=source&distro=trusty/esm
Affected ranges
Type: ECOSYSTEM
Events:
