CVE-2022-32743Incorrect Default Permissions in Samba

Severity
7.5HIGHNVD
EPSS
1.2%
top 21.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 1
Latest updateSep 13

Description

Samba does not validate the Validated-DNS-Host-Name right for the dNSHostName attribute which could permit unprivileged users to write it.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages5 packages

NVDsamba/samba4.1.04.17.0
debiandebian/samba< samba 2:4.17.2+dfsg-3 (bookworm)
Debiansamba/samba< 2:4.17.2+dfsg-3+2
CVEListV5samba/sambasamba 4.1 and newer

Also affects: Fedora 37

Patches

🔴Vulnerability Details

2
GHSA
GHSA-57p4-2x7w-phr2: Samba does not validate the Validated-DNS-Host-Name right for the dNSHostName attribute which could permit unprivileged users to write it2022-09-02
OSV
CVE-2022-32743: Samba does not validate the Validated-DNS-Host-Name right for the dNSHostName attribute which could permit unprivileged users to write it2022-09-01

📋Vendor Advisories

3
Microsoft
Samba does not validate the Validated-DNS-Host-Name right for the dNSHostName attribute which could permit unprivileged users to write it.2022-09-13
Red Hat
samba: Validated dnsHostname write right needs to be implemented2022-08-24
Debian
CVE-2022-32743: samba - Samba does not validate the Validated-DNS-Host-Name right for the dNSHostName at...2022