CVE-2022-3437 is a heap-based buffer overflow vulnerability in Samba's GSSAPI unwrap_des() and unwrap_des3() routines, specifically affecting Heimdal's DES and Triple-DES decryption. This flaw allows a remote attacker to trigger a denial of service (DoS) by sending specially crafted, small packets to affected Samba installations, including various Fedora and Samba versions. Rated as MEDIUM severity with a CVSS score of 6.5, it requires low privileges and network access for exploitation, but has no impact on confidentiality or integrity. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage, indicating a low immediate threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.0.0, < 4.15.11CPE matchmatch criteria | cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* | ||
>= 4.16.0, < 4.16.6CPE matchmatch criteria | cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* | ||
>= 4.17.0, < 4.17.2CPE matchmatch criteria | cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* | ||
36CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:* | ||
37CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2022-3437
Oct 8, 2024A heap-based buffer overflow vulnerability was found in Samba within the GSSAPI unwrap_des() and unwrap_des3() routines of Heimdal. The DES and Triple-DES decryption routines in the Heimdal GSSAPI library allow a length-limited write buffer overflow on malloc() allocated memory when presented with a maliciously small packet. This flaw allows a remote user to send specially crafted malicious data to the application possibly resulting in a denial of service (DoS) attack.
Jan 10, 2023AS-2022-016: Samba
Dec 27, 2022samba: heap buffer overflow in GSSAPI unwrap_des() and unwrap_des3() routines of Heimdal
Oct 25, 2022