Vulnerability in Samba and MIT/Heimdal Kerberos that leads to buffer overflow.
Correction releases of Samba package 4.17.3, 4.16.7, and 4.15.12 have been published, addressing the vulnerability (CVE-2022-42898) in Kerberos libraries, which leads to integer overflow and out-of-bounds data write when processing PAC (Privileged Attribute Certificate) parameters sent by an authenticated user. The publication of package updates in distributions can be tracked on the following pages: Debian, Ubuntu, Gentoo, RHEL, SUSE, Arch, FreeBSD. In addition to Samba […]
