UBUNTU-CVE-2022-45141
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-45141
UBUNTU-CVE-2022-45141
Summary:
Details: Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was disclosed by Microsoft on Nov 8 2022 and per RFC8429 it is assumed that rc4-hmac is weak, Vulnerable Samba Active Directory DCs will issue rc4-hmac encrypted tickets despite the target server supporting better encryption (eg aes256-cts-hmac-sha1-96).
References: https://ubuntu.com/security/CVE-2022-45141, https://www.samba.org/samba/security/CVE-2022-45141.html, https://ubuntu.com/security/notices/USN-5822-1, https://ubuntu.com/security/notices/USN-5822-2, https://ubuntu.com/security/notices/USN-5936-1, https://www.cve.org/CVERecord?id=CVE-2022-45141, https://ubuntu.com/security/notices/USN-7582-1
Affected packages
Package
Name: samba
Purl: pkg:deb/ubuntu/samba@2:4.3.11+dfsg-0ubuntu0.16.04.34+esm2?arch=source&distro=esm-infra/xenial
Affected ranges
Type: ECOSYSTEM
Events:
