CVE-2022-3437
unknown
CVSS v3
—
CVSS v4 NEW
—
VIR risk
—
Description
macOS Sequoia 15.8
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Mitigation details
Source: Debian Security Tracker · View original ↗ · DFSG
CVE-2022-3437 NameCVE-2022-3437 DescriptionA heap-based buffer overflow vulnerability was found in Samba within the GSSAPI unwrap_des() and unwrap_des3() routines of Heimdal. The DES and Triple-DES decryption routines in the Heimdal GSSAPI library allow a length-limited write buffer overflow on malloc() allocated memory when presented with a maliciously small packet. This flaw allows a remote…
CVE-2022-3437
| Name | CVE-2022-3437 |
| Description | A heap-based buffer overflow vulnerability was found in Samba within the GSSAPI unwrap_des() and unwrap_des3() routines of Heimdal. The DES and Triple-DES decryption routines in the Heimdal GSSAPI library allow a length-limited write buffer overflow on malloc() allocated memory when presented with a maliciously small packet. This flaw allows a remote user to send specially crafted malicious data to the application, possibly resulting in a denial of service (DoS) attack. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
| References | DLA-3206-1, DLA-3792-1, DSA-5287-1, DSA-5647-1 |
| Debian Bugs | 1024187 |
Vulnerable and fixed packages
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|---|---|---|
| heimdal (PTS) | bookworm | 7.8.git20221117.28daf24+dfsg-2 | fixed |
| trixie | 7.8.git20221117.28daf24+dfsg-9+deb13u1 | fixed | |
| forky, sid | 7.8.git20240113.1b4565a+dfsg-2 | fixed | |
| samba (PTS) | bookworm, bookworm (security) | 2:4.17.12+dfsg-0+deb12u4 | fixed |
| trixie | 2:4.22.10+dfsg-0+deb13u1 | fixed | |
| trixie (security) | 2:4.22.10+dfsg-0+deb13u2 | fixed | |
| forky, sid | 2:4.24.6+dfsg-1 | fixed |
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|---|---|---|---|---|---|
| heimdal | source | buster | 7.5.0+dfsg-3+deb10u1 | DLA-3206-1 | ||
| heimdal | source | bullseye | 7.7.0+dfsg-2+deb11u2 | DSA-5287-1 | ||
| heimdal | source | (unstable) | 7.8.git20221115.a6cf945+dfsg-1 | 1024187 | ||
| samba | source | buster | 2:4.9.5+dfsg-5+deb10u5 | DLA-3792-1 | ||
| samba | source | bullseye | 2:4.13.13+dfsg-1~deb11u6 | DSA-5647-1 | ||
| samba | source | (unstable) | 2:4.16.6+dfsg-1 |
Notes
https://www.samba.org/samba/security/CVE-2022-3437.html
https://bugzilla.samba.org/show_bug.cgi?id=15134
https://github.com/heimdal/heimdal/security/advisories/GHSA-45j3-5v39-rf9j
https://github.com/heimdal/heimdal/commit/f6edaafcfefd843ca1b1a041f942a853d85ee7c3 (heimdal-7.7.1)
https://github.com/heimdal/heimdal/commit/c9cc34334bd64b08fe91a2f720262462e9f6bb49 (heimdal-7.7.1)
https://github.com/heimdal/heimdal/commit/a587a4bcb28d5b9047f332573b1e7c8f89ca3edd (heimdal-7.7.1)
https://github.com/heimdal/heimdal/commit/c758910eaad3c0de2cfb68830a661c4739675a7d (heimdal-7.7.1)
https://github.com/heimdal/heimdal/commit/414b2a77fd61c26d64562e3800dc5578d9d0f15d (heimdal-7.7.1)
https://github.com/heimdal/heimdal/commit/be9bbd93ed8f204b4bc1b92d1bc3c16aac194696 (heimdal-7.7.1)
https://github.com/heimdal/heimdal/commit/c8407ca079294d76a5ed140ba5b546f870d23ed2 (heimdal-7.7.1)
https://github.com/heimdal/heimdal/commit/8fb508a25a6a47289c73e3f4339352a73a396eef (heimdal-7.7.1)
In scope for continued Samba support
possible samba 4.13,4.15 regression: https://bugzilla.samba.org/show_bug.cgi?id=15243
and https://bugs.launchpad.net/ubuntu/+source/samba/+bug/2003867
Apply commands
Notes
https://www.samba.org/samba/security/CVE-2022-3437.htmlhttps://bugzilla.samba.org/show_bug.cgi?id=15134https://github.com/heimdal/heimdal/security/advisories/GHSA-45j3-5v39-rf9jhttps://github.com/heimdal/heimdal/commit/f6edaafcfefd843ca1b1a041f942a853d85ee7c3 (heimdal-7.7.1)https://github.com/heimdal/heimdal/commit/c9cc34334bd64b08fe91a2f720262462e9f6bb49 (heimdal-7.7.1)https://github.com/heimdal/heimdal/commit/a587a4bcb28d5b9047f332573b1e7c8f89ca3edd (heimdal-7.7.1)https://github.com/heimdal/heimdal/commit/c758910eaad3c0de2cfb68830a661c4739675a7d (heimdal-7.7.1)https://github.com/heimdal/heimdal/commit/414b2a77fd61c26d64562e3800dc5578d9d0f15d (heimdal-7.7.1)https://github.com/heimdal/heimdal/commit/be9bbd93ed8f204b4bc1b92d1bc3c16aac194696 (heimdal-7.7.1)https://github.com/heimdal/heimdal/commit/c8407ca079294d76a5ed140ba5b546f870d23ed2 (heimdal-7.7.1)https://github.com/heimdal/heimdal/commit/8fb508a25a6a47289c73e3f4339352a73a396eef (heimdal-7.7.1)In scope for continued Samba supportpossible samba 4.13,4.15 regression: https://bugzilla.samba.org/show_bug.cgi?id=15243and https://bugs.launchpad.net/ubuntu/+source/samba/+bug/2003867
OS impact
SUSE Affected 1 release
| Version | Status | Fixed in |
|---|---|---|
| — | Affected | — |
Alpine Fixed 4 releases
| Version | Status | Fixed in |
|---|---|---|
| v3.24 | Fixed | 7.7.1-r0 |
| v3.23 | Fixed | 7.7.1-r0 |
| v3.22 | Fixed | 7.7.1-r0 |
| v3.21 | Fixed | 7.7.1-r0 |
Arch Fixed 1 release
| Version | Status | Fixed in |
|---|---|---|
| — | Fixed | 4.17.5-1 |
Debian Fixed 5 releases
| Version | Status | Fixed in |
|---|---|---|
| trixie | Fixed | 7.8.git20221115.a6cf945+dfsg-1 |
| sid | Fixed | 7.8.git20221115.a6cf945+dfsg-1 |
| forky | Fixed | 7.8.git20221115.a6cf945+dfsg-1 |
| bullseye | Fixed | 7.7.0+dfsg-2+deb11u2 |
| bookworm | Fixed | 7.8.git20221115.a6cf945+dfsg-1 |
macOS Fixed 3 releases
| Version | Status | Fixed in |
|---|---|---|
| 26.7 | Fixed | — |
| 15.8 | Fixed | — |
| — | Fixed | — |
References
- https://www.suse.com/security/cve/CVE-2022-3437.html
- https://security-tracker.debian.org/tracker/CVE-2022-3437
- https://security.alpinelinux.org/vuln/CVE-2022-3437
- https://pkgs.alpinelinux.org/packages?name=heimdal
- https://pkgs.alpinelinux.org/packages?name=samba
- https://support.apple.com/en-us/149035
- https://support.apple.com/en-us/149042
- https://support.apple.com/en-us/149043
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.