Search CVE reports


Toggle filters

21 – 30 of 191 results


CVE-2022-3592

Medium priority
Not affected

A symlink following vulnerability was found in Samba, where a user can create a symbolic link that will make 'smbd' escape the configured share path. This flaw allows a remote user with access to the exported part of the file...

1 affected package

samba

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba Not affected Not affected Not affected
Show less packages

CVE-2022-3437

Medium priority

Some fixes available 15 of 17

A heap-based buffer overflow vulnerability was found in Samba within the GSSAPI unwrap_des() and unwrap_des3() routines of Heimdal. The DES and Triple-DES decryption routines in the Heimdal GSSAPI library allow a length-limited...

2 affected packages

heimdal, samba

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
heimdal Not affected Vulnerable Fixed Fixed
samba Fixed Fixed Fixed Fixed
Show less packages

CVE-2022-32746

Medium priority

Some fixes available 10 of 18

A flaw was found in the Samba AD LDAP server. The AD DC database audit logging module can access LDAP message values freed by a preceding database module, resulting in a use-after-free issue. This issue is only possible when...

2 affected packages

ldb, samba

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ldb Not in release Fixed Fixed Ignored
samba Fixed Fixed Fixed Ignored
Show less packages

CVE-2022-32745

Medium priority

Some fixes available 8 of 12

A flaw was found in Samba. Samba AD users can cause the server to access uninitialized data with an LDAP add or modify the request, usually resulting in a segmentation fault.

1 affected package

samba

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba Fixed Fixed Fixed Ignored
Show less packages

CVE-2022-32744

Medium priority

Some fixes available 8 of 12

A flaw was found in Samba. The KDC accepts kpasswd requests encrypted with any key known to it. By encrypting forged kpasswd requests with its own key, a user can change other users' passwords, enabling full domain takeover.

1 affected package

samba

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba Fixed Fixed Fixed Ignored
Show less packages

CVE-2022-32743

Low priority
Vulnerable

Samba does not validate the Validated-DNS-Host-Name right for the dNSHostName attribute which could permit unprivileged users to write it.

1 affected package

samba

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba Not affected Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2022-32742

Low priority

Some fixes available 8 of 12

A flaw was found in Samba. Some SMB1 write requests were not correctly range-checked to ensure the client had sent enough data to fulfill the write, allowing server memory contents to be written into the file (or printer) instead...

1 affected package

samba

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba Fixed Fixed Fixed Vulnerable
Show less packages

CVE-2022-3116

Medium priority

Some fixes available 4 of 11

The Heimdal Software Kerberos 5 implementation is vulnerable to a null pointer dereferance. An attacker with network access to an application that depends on the vulnerable code path can cause the application to crash.

2 affected packages

samba, heimdal

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba Not affected Not affected Not affected Not affected
heimdal Vulnerable Vulnerable Fixed Fixed
Show less packages

CVE-2022-2127

Medium priority

Some fixes available 8 of 11

An out-of-bounds read vulnerability was found in Samba due to insufficient length checks in winbindd_pam_auth_crap.c. When performing NTLM authentication, the client replies to cryptographic challenges back to the server. These...

1 affected package

samba

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba Fixed Fixed Fixed Needs evaluation
Show less packages

CVE-2022-2031

Medium priority

Some fixes available 8 of 12

A flaw was found in Samba. The security vulnerability occurs when KDC and the kpasswd service share a single account and set of keys, allowing them to decrypt each other's tickets. A user who has been requested to change their...

1 affected package

samba

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
samba Fixed Fixed Fixed Ignored
Show less packages