Samba Releases Security Updates October 2022
Security updates address two vulnerabilities
Summary
Security updates address two vulnerabilities
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Samba has released security updates to address two vulnerabilities in multiple versions of Samba, a standard Windows interoperability suite of programs for Linux and Unix. These vulnerabilities are CVE-2022-3437, which has a score of 5.9 on the CVSSv3 scale. The DES (for Samba 4.11 and earlier) and Triple-DES decryption routines in the Heimdal library allow a length-limited write buffer overflow on malloc() allocated memory when presented with a maliciously small packet. The vulnerability known as CVE-2022-3592 has a score of 5.4 and allows a malicious client to use a symlink to escape the exported directory.
An attacker could exploit these to take control of a vulnerable system.
Remediation advice
Affected organisations are encouraged to review the following Samba Security Announcements and apply any relevant updates or workarounds.
Remediation steps
| Type | Step |
|---|---|
| Patch |
CVE-2022-3437 https://www.samba.org/samba/security/CVE-2022-3437.html |
| Patch |
CVE-2022-3592 https://www.samba.org/samba/security/CVE-2022-3592.html |
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 26 October 2022 4:08 pm