Logo
vulnerabilityCVE-2022-3437
Name
CVE-2022-3437
Source
NVD ( link)Debian ( link)
Description
A heap-based buffer overflow vulnerability was found in Samba within the GSSAPI unwrap_des() and unwrap_des3() routines of Heimdal. The DES and Triple-DES decryption routines in the Heimdal GSSAPI library allow a length-limited write buffer overflow on malloc() allocated memory when presented with a maliciously small packet. This flaw allows a remote user to send specially crafted malicious data to the application, possibly resulting in a denial of service (DoS) attack.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
samba
Patched

Vulnerability Ratings#


6.5
CVSSv31
4.3
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
4.22.10
Not Affected
buildroot
master
4.24.3
Not Affected
openwrt
master
4.22.7-r3
Not Affected
openwrt
openwrt-25.12
4.22.7-r3
Not Affected
yocto
master
4.23.5
Not Affected
yocto
scarthgap
4.19.9
Not Affected

Resolved with patches#


samba (yocto:kirkstone)

#
Title
Author
Resolve
1
gsskrb5: CVE-2022-3437 Check for overflow in
Joseph Sutton <josephsutton@catalyst.net.nz>
CVE-2022-3437
2
gsskrb5: CVE-2022-3437 Check buffer length against overflow
Joseph Sutton <josephsutton@catalyst.net.nz>
CVE-2022-3437
3
gsskrb5: CVE-2022-3437 Don't pass NULL pointers to memcpy()
Joseph Sutton <josephsutton@catalyst.net.nz>
CVE-2022-3437
4
gsskrb5: CVE-2022-3437 Check the result of
Joseph Sutton <josephsutton@catalyst.net.nz>
CVE-2022-3437
5
gsskrb5: CVE-2022-3437 Pass correct length to
Joseph Sutton <josephsutton@catalyst.net.nz>
CVE-2022-3437
6
gsskrb5: CVE-2022-3437 Use constant-time memcmp() for arcfour
Joseph Sutton <josephsutton@catalyst.net.nz>
CVE-2022-3437
7
gsskrb5: CVE-2022-3437 Use constant-time memcmp() in
Joseph Sutton <josephsutton@catalyst.net.nz>
CVE-2022-3437
8
gsskrb5: CVE-2022-3437 Avoid undefined behaviour in
Joseph Sutton <josephsutton@catalyst.net.nz>
CVE-2022-3437