Skip to main content

Samba Releases Security Updates October 2022

Security updates address two vulnerabilities

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Security updates address two vulnerabilities


Affected platforms

The following platforms are known to be affected:

Threat details

Introduction

Samba has released security updates to address two vulnerabilities in multiple versions of Samba, a standard Windows interoperability suite of programs for Linux and Unix. These vulnerabilities are CVE-2022-3437, which has a score of 5.9 on the CVSSv3 scale. The DES (for Samba 4.11 and earlier) and Triple-DES decryption routines in the Heimdal library allow a length-limited write buffer overflow on malloc() allocated memory when presented with a maliciously small packet. The vulnerability known as CVE-2022-3592 has a score of 5.4 and allows a malicious client to use a symlink to escape the exported directory.

An attacker could exploit these to take control of a vulnerable system. 


Remediation advice

Affected organisations are encouraged to review the following Samba Security Announcements and apply any relevant updates or workarounds.



Definitive source of threat updates


Last edited: 26 October 2022 4:08 pm