USN-5542-1

    Dashboard / Vulnerabilities / USN-5542-1

    USN-5542-1

    Published: 1 Aug 2022Last Modified: 27 Apr 2026

    Summary: samba vulnerabilities

    Details: It was discovered that Samba did not handle MaxQueryDuration when being used in AD DC configurations, contrary to expectations. This issue only affected Ubuntu 20.04 LTS. (CVE-2021-3670) Luke Howard discovered that Samba incorrectly handled certain restrictions associated with changing passwords. A remote attacker being requested to change passwords could possibly use this issue to escalate privileges. (CVE-2022-2031) Luca Moro discovered that Samba incorrectly handled certain SMB1 communications. A remote attacker could possibly use this issue to obtain sensitive memory contents. (CVE-2022-32742) Joseph Sutton discovered that Samba incorrectly handled certain password change requests. A remote attacker could use this issue to change passwords of other users, resulting in privilege escalation. (CVE-2022-32744) Joseph Sutton discovered that Samba incorrectly handled certain LDAP add or modify requests. A remote attacker could possibly use this issue to cause Samba to crash, resulting in a denial of service. (CVE-2022-32745) Joseph Sutton and Andrew Bartlett discovered that Samba incorrectly handled certain LDAP add or modify requests. A remote attacker could possibly use this issue to cause Samba to crash, resulting in a denial of service. (CVE-2022-32746)

    Affected packages

    Package

    Name: samba

    Purl: pkg:deb/ubuntu/samba@2:4.13.17~dfsg-0ubuntu1.20.04.1?arch=source&distro=focal

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -2:4.13.17~dfsg-0ubuntu1.20.04.1

    Affected versions

    2:4.10.7+dfsg-0ubuntu2
    2:4.10.7+dfsg-0ubuntu3

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    USN-5542-1 | CVE-DB