Corrective releases of Samba package versions 4.17.2, 4.16.6, and 4.15.11 have been published, addressing two vulnerabilities. You can track the package update releases in the distributions on the pages: Debian, Ubuntu, Gentoo, RHEL, SUSE, Arch, FreeBSD.
- CVE-2022-3437 - a buffer overflow in the unwrap_des() and unwrap_des3() functions provided in the GSSAPI library from the Heimdal package (included with Samba since version 4.0). Exploitation of this vulnerability is possible by sending a specially crafted packet to systems using GSSAPI. For example, the problem manifests in the client and file implementation server based on the SMB1 protocol, when using DCE/RPC and in Active Directory domain controllers. Systems built with MIT Kerberos (--with-system-mitkrb5) instead of Heimdal are not affected by this issue.
- CVE-2022-3592 - a possibility of exceeding the boundaries of the exported directory and accessing any file on server through manipulation of symbolic links. This issue occurs only in the Samba 4.17 branch and is caused by an error in the new code for handling symbolic links in user space (the code lacked a check for whether the target directory of the link was outside the exported directory). The vulnerability can be exploited by a client with write access to the exported partition provided through SMB1 or NFS protocols, which allow the creation of symbolic links.
Source: opennet.ru
