Vulnerability in Samba and MIT/Heimdal Kerberos that leads to buffer overflow.

Corrective releases of Samba packages 4.17.3, 4.16.7, and 4.15.12 have been published to address a vulnerability (CVE-2022-42898) in the Kerberos libraries, leading to integer overflow and out-of-bounds data writes when processing PAC (Privileged Attribute Certificate) parameters sent by an authenticated user. You can track the release of package updates in the distributions on the following pages: Debian, Ubuntu, Gentoo, RHEL, SUSE, Arch, FreeBSD.

In addition to Samba, the issue also manifests in packages with MIT Kerberos and Heimdal Kerberos. The Samba project vulnerability report does not detail the threat, but the MIT Kerberos report indicates that the vulnerability could lead to remote code execution. Exploitation of the vulnerability is possible only on 32-bit systems.

The issue affects configurations with KDC (Key Distribution Center) or kadmind. In configurations without Active Directory, the vulnerability also appears on Samba file servers using Kerberos. servers The problem is caused by an error in the function krb5_parse_pac(), which incorrectly calculated the size of the buffer used when parsing PAC fields. On 32-bit systems, processing specially crafted PACs could lead to the placement of a 16-byte block sent by an attacker outside the allocated buffer.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster