CVE-2022-42898
published 2022-12-25CVE-2022-42898: PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind…
PriorityP357high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
6.42%
93.0th percentile
PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has "a similar bug."
Affected
51 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | heimdal | < heimdal 7.8.git20221115.a6cf945+dfsg-1 (bookworm) | heimdal 7.8.git20221115.a6cf945+dfsg-1 (bookworm) |
| debian | krb5 | < heimdal 7.8.git20221115.a6cf945+dfsg-1 (bookworm) | heimdal 7.8.git20221115.a6cf945+dfsg-1 (bookworm) |
| debian | samba | < heimdal 7.8.git20221115.a6cf945+dfsg-1 (bookworm) | heimdal 7.8.git20221115.a6cf945+dfsg-1 (bookworm) |
| heimdal_project | heimdal | < 7.7.1 | 7.7.1 |
| heimdal_project | heimdal | >= 0 < 7.7.0+dfsg-2+deb11u2 | 7.7.0+dfsg-2+deb11u2 |
| heimdal_project | heimdal | >= 0 < 7.8.git20221115.a6cf945+dfsg-1 | 7.8.git20221115.a6cf945+dfsg-1 |
| heimdal_project | heimdal | >= 0 < 7.8.git20221115.a6cf945+dfsg-1 | 7.8.git20221115.a6cf945+dfsg-1 |
| heimdal_project | heimdal | >= 0 < 7.8.git20221115.a6cf945+dfsg-1 | 7.8.git20221115.a6cf945+dfsg-1 |
| heimdal_project | heimdal | >= 0 < 7.5.0+dfsg-1ubuntu0.3 | 7.5.0+dfsg-1ubuntu0.3 |
| heimdal_project | heimdal | >= 0 < 7.7.0+dfsg-1ubuntu1.3 | 7.7.0+dfsg-1ubuntu1.3 |
| heimdal_project | heimdal | >= 0 < 1.6~git20131207+dfsg-1ubuntu1.2+esm3 | 1.6~git20131207+dfsg-1ubuntu1.2+esm3 |
| heimdal_project | heimdal | >= 0 < 1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm3 | 1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm3 |
| mit | kerberos_5 | — | — |
| mit | kerberos_5 | >= 1.8 < 1.19.4 | 1.19.4 |
| mit | krb5 | >= 0 < 1.18.3-6+deb11u3 | 1.18.3-6+deb11u3 |
| mit | krb5 | >= 0 < 1.20.1-1 | 1.20.1-1 |
| mit | krb5 | >= 0 < 1.20.1-1 | 1.20.1-1 |
| mit | krb5 | >= 0 < 1.20.1-1 | 1.20.1-1 |
| mit | krb5 | >= 0 < 1.16-2ubuntu0.3 | 1.16-2ubuntu0.3 |
| mit | krb5 | >= 0 < 1.17-6ubuntu4.2 | 1.17-6ubuntu4.2 |
| mit | krb5 | >= 0 < 1.19.2-2ubuntu0.1 | 1.19.2-2ubuntu0.1 |
| mit | krb5 | >= 0 < 1.12+dfsg-2ubuntu5.4+esm3 | 1.12+dfsg-2ubuntu5.4+esm3 |
| mit | krb5 | >= 0 < 1.13.2+dfsg-5ubuntu2.2+esm3 | 1.13.2+dfsg-5ubuntu2.2+esm3 |
| msrc | azl3_samba_4.18.3-1_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for integer overflow conditions during PAC (Privilege Attribute Certificate) parsing in KDC, kadmind, or GSS/Kerberos application servers, particularly on 32-bit platforms where a heap-based buffer overflow may result. ↗
- →Focus detection on the krb5_pac_parse function in lib/krb5/krb/pac.c — malformed or oversized PAC buffers triggering integer overflow in this function are the attack vector. ↗
- →Heimdal KDC deployments prior to 7.7.1 are also vulnerable to a similar PAC parsing bug; monitor Heimdal KDC processes for anomalous PAC-related crashes or heap corruption. ↗
- →Watch for unexpected crashes or restarts of kadmind, KDC, or SPNEGO-enabled application servers, which may indicate exploitation attempts via malformed PAC data. ↗
- →On FreeBSD systems, check for Heimdal-related process anomalies; the advisory covers multiple CVEs including CVE-2022-42898 (PAC parse integer overflows) alongside CVE-2022-44640 (invalid free in ASN.1 codec) which may be chained. ↗
- ·Exploitation leading to remote code execution is limited to 32-bit platforms due to the resultant heap-based buffer overflow; 64-bit platforms are only subject to denial of service. ↗
- ·Only systems using Kerberos are affected; non-Kerberos deployments are not at risk. ↗
- ·On FreeBSD specifically, CVE-2022-44640 (a related severe vulnerability) cannot be exploited for RCE, though CVE-2022-42898 remains applicable. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
vendor_msrc8.8HIGH
vendor_oracle8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Samba regression
vendor_ubuntu·2025-06-30·CVSS 6.5
CVE-2022-3437 [MEDIUM] Samba regression
Title: Samba regression
Summary: USN-7582-1 introduced a regression in Samba.
USN-7582-1 fixed vulnerabilities in Samba. The update introduced a
regression. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Evgeny Legerov discovered that Samba incorrectly handled buffers in
certain GSSAPI routines of Heimdal. A remote attacker could possibly use
this issue to cause Samba to crash, resulting in a denial of service.
(CVE-2022-3437)
Greg Hudson discovered that Samba incorrectly handled PAC parsing. On
32-bit systems, a remote attacker could use this issue to escalate
privileges, or possibly execute arbitrary code. (CVE-2022-42898)
Joseph Sutton discovered that Samba could be forced to issue rc4-hmac
encrypted Kerberos tickets. A remote attack
Ubuntu
Samba vulnerabilities
vendor_ubuntu·2025-06-19·CVSS 6.5
CVE-2023-34966 [MEDIUM] Samba vulnerabilities
Title: Samba vulnerabilities
Summary: Several security issues were fixed in Samba.
Evgeny Legerov discovered that Samba incorrectly handled buffers in
certain GSSAPI routines of Heimdal. A remote attacker could possibly use
this issue to cause Samba to crash, resulting in a denial of service.
(CVE-2022-3437)
Greg Hudson discovered that Samba incorrectly handled PAC parsing. On
32-bit systems, a remote attacker could use this issue to escalate
privileges, or possibly execute arbitrary code. (CVE-2022-42898)
Joseph Sutton discovered that Samba could be forced to issue rc4-hmac
encrypted Kerberos tickets. A remote attacker could possibly use this issue
to escalate privileges. This issue only affected Ubuntu 20.04 LTS and
Ubuntu 22.04 LTS. (CVE-2022-45141)
Florent Saudel discovered that S
CISA ICS
ABB M2M Gateway
cisa_ics·2025-04-15
ABB M2M Gateway
ICS Advisory
##
ABB M2M Gateway
Release DateApril 15, 2025
Alert CodeICSA-25-105-08
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 8.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: ABB
- Equipment: M2M Gateway
- Vulnerabilities: Integer Overflow or Wraparound, Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), Unquoted Search Path or Element, Untrusted Search Path, Use After Free, Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Missing Release of Memory after Effective Lifetime, Allocation of Resources Without Limits or Throttling, Improper Privilege Management, Improper Limitati
Palo Alto
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-02-14·CVSS 9.8
CVE-2017-18342 [CRITICAL] PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2017-18342, CVE-2017-8923, CVE-2017-9120, CVE-2019-1551, CVE-2019-16865, CVE-2019-16905, CVE-2019-19523, CVE-2019-19528, CVE-2019-19911, CVE-2020-0404, CVE-2020-0431, CVE-2020-0466, CVE-2020-10379, CVE-2020-11538, CVE-2020-11608, CVE-2020-12114, CVE-2020-12321, CVE-2020-12362, CVE-2020-12363, CVE-2020-12364, CVE-2020-13757, CVE-2020-14314, CVE-2020-14351, CVE-2020-15778, CVE-2020-1967, CVE-2020-24394, CVE-2020-24504, CVE-2020-25211, CVE-2020-25212, CVE-2020-25284, CVE-2020-25285, CVE-2020-25717, CVE-2020-26541, CVE-2020-2715
Oracle
Oracle Oracle MySQL Risk Matrix: Cluster: General (Kerberos) — CVE-2022-42898
vendor_oracle·2023-10-15·CVSS 8.8
CVE-2022-42898 [HIGH] Oracle Oracle MySQL Risk Matrix: Cluster: General (Kerberos) — CVE-2022-42898
Oracle Oracle MySQL Risk Matrix: Cluster: General (Kerberos) vulnerability
CVE: CVE-2022-42898
CVSS: 8.8
Protocol: Multiple
Remote exploit: No
Affected versions: Network
Advisory: cpuoct2023 (OCT 2023)
Oracle
Oracle Oracle Communications Risk Matrix: Install/Upgrade (Kerberos) — CVE-2022-42898
vendor_oracle·2023-07-15·CVSS 8.8
CVE-2022-42898 [HIGH] Oracle Oracle Communications Risk Matrix: Install/Upgrade (Kerberos) — CVE-2022-42898
Oracle Oracle Communications Risk Matrix: Install/Upgrade (Kerberos) vulnerability
CVE: CVE-2022-42898
CVSS: 8.8
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpujul2023 (JUL 2023)
Oracle
Oracle Oracle Communications Risk Matrix: Installation and Configuration (Kerberos) — CVE-2022-42898
vendor_oracle·2023-04-15·CVSS 8.8
CVE-2022-42898 [HIGH] Oracle Oracle Communications Risk Matrix: Installation and Configuration (Kerberos) — CVE-2022-42898
Oracle Oracle Communications Risk Matrix: Installation and Configuration (Kerberos) vulnerability
CVE: CVE-2022-42898
CVSS: 8.8
Protocol: Kerberos
Remote exploit: No
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Ubuntu
Samba vulnerabilities
vendor_ubuntu·2023-03-08·CVSS 6.5
CVE-2022-37966 [MEDIUM] Samba vulnerabilities
Title: Samba vulnerabilities
Summary: Several security issues were fixed in Samba.
Evgeny Legerov discovered that Samba incorrectly handled buffers in
certain GSSAPI routines of Heimdal. A remote attacker could possibly use
this issue to cause Samba to crash, resulting in a denial of service.
(CVE-2022-3437)
Tom Tervoort discovered that Samba incorrectly used weak rc4-hmac Kerberos
keys. A remote attacker could possibly use this issue to elevate
privileges. (CVE-2022-37966, CVE-2022-37967)
It was discovered that Samba supported weak RC4/HMAC-MD5 in NetLogon Secure
Channel. A remote attacker could possibly use this issue to elevate
privileges. (CVE-2022-38023)
Greg Hudson discovered that Samba incorrectly handled PAC parsing. On
32-bit systems, a remote attacker could use this issue to
Ubuntu
Samba regression
vendor_ubuntu·2023-01-26·CVSS 5.9
[MEDIUM] Samba regression
Title: Samba regression
Summary: USN 5822-1 introduced regressions on Ubuntu 20.04 LTS.
USN-5822-1 fixed vulnerabilities in Samba. The update for Ubuntu 20.04 LTS
introduced regressions in certain environments. Pending investigation of
these regressions, this update temporarily reverts the security fixes.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Samba incorrectly handled the bad password count
logic. A remote attacker could possibly use this issue to bypass bad
passwords lockouts. This issue was only addressed in Ubuntu 22.10.
(CVE-2021-20251)
Evgeny Legerov discovered that Samba incorrectly handled buffers in
certain GSSAPI routines of Heimdal. A remote attacker could possibly use
this issue to cause Samba to crash, resulting in a denial
Ubuntu
Kerberos vulnerabilities
vendor_ubuntu·2023-01-25·CVSS 5.3
CVE-2022-42898 [MEDIUM] Kerberos vulnerabilities
Title: Kerberos vulnerabilities
Summary: Several security issues were fixed in Kerberos.
It was discovered that Kerberos incorrectly handled certain S4U2Self
requests. An attacker could possibly use this issue to cause a denial of
service. This issue was only addressed in Ubuntu 16.04 ESM and Ubuntu
18.04 LTS. (CVE-2018-20217)
Greg Hudson discovered that Kerberos PAC implementation incorrectly
handled certain parsing operations. A remote attacker could use this
issue to cause a denial of service, or possibly execute arbitrary code.
(CVE-2022-42898)
Instructions: After a standard system update you need to restart any application
using Kerberos libraries to make all the necessary changes.
Ubuntu
Samba vulnerabilities
vendor_ubuntu·2023-01-24·CVSS 5.9
CVE-2022-37966 [MEDIUM] Samba vulnerabilities
Title: Samba vulnerabilities
Summary: Several security issues were fixed in Samba.
It was discovered that Samba incorrectly handled the bad password count
logic. A remote attacker could possibly use this issue to bypass bad
passwords lockouts. This issue was only addressed in Ubuntu 22.10.
(CVE-2021-20251)
Evgeny Legerov discovered that Samba incorrectly handled buffers in
certain GSSAPI routines of Heimdal. A remote attacker could possibly use
this issue to cause Samba to crash, resulting in a denial of service.
(CVE-2022-3437)
Tom Tervoort discovered that Samba incorrectly used weak rc4-hmac Kerberos
keys. A remote attacker could possibly use this issue to elevate
privileges. (CVE-2022-37966, CVE-2022-37967)
It was discovered that Samba supported weak RC4/HMAC-MD5 in NetLogon Secure
Ubuntu
Heimdal vulnerabilities
vendor_ubuntu·2023-01-12·CVSS 7.5
CVE-2022-42898 [HIGH] Heimdal vulnerabilities
Title: Heimdal vulnerabilities
Summary: Several security issues were fixed in Heimdal.
It was discovered that Heimdal incorrectly handled certain SPNEGO tokens. A
remote attacker could possibly use this issue to cause a denial of service.
(CVE-2021-44758)
Evgeny Legerov discovered that Heimdal incorrectly handled memory when
performing certain DES decryption operations. A remote attacker could use
this issue to cause a denial of service, or possibly execute arbitrary
code. (CVE-2022-3437)
Greg Hudson discovered that Kerberos PAC implementation used in Heimdal
incorrectly handled certain parsing operations. A remote attacker could use
this issue to cause a denial of service, or possibly execute arbitrary
code. (CVE-2022-42898)
It was discovered that Heimdal's KDC did not properly handl
Microsoft
PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC kadmind or a GSS or Kerberos application server) on
vendor_msrc·2022-12-13·CVSS 8.8
CVE-2022-42898 [HIGH] CWE-190 PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC kadmind or a GSS or Kerberos application server) on
PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC kadmind or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow) and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has "a similar bug."
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Micr
BSD
FreeBSD-SA-22:14.heimdal: Multiple vulnerabilities in Heimdal [REVISED]
bsd_advisories·2022-11-15·CVSS 5.4
CVE-2019-14870 [MEDIUM] FreeBSD-SA-22:14.heimdal: Multiple vulnerabilities in Heimdal [REVISED]
FreeBSD-SA-22:14.heimdal Security Advisory
The FreeBSD Project
Topic: Multiple vulnerabilities in Heimdal [REVISED]
Category: contrib
Module: heimdal
Announced: 2022-11-15
Revised: 2022-11-29
Affects: All supported versions of FreeBSD.
Corrected: 2022-11-15 21:15:35 UTC (stable/13, 13.1-STABLE)
2022-11-16 01:50:27 UTC (releng/13.1, 13.1-RELEASE-p4)
2022-11-15 21:16:56 UTC (stable/12, 12.4-STABLE)
2022-11-16 01:47:57 UTC (releng/12.4, 12.4-RC2-p1)
2022-11-16 01:40:21 UTC (releng/12.3, 12.3-RELEASE-p9)
CVE Name: CVE-2019-14870, CVE-2022-3437, CVE-2022-42898,
CVE-2022-44640, CVE-2021-44758
0. Revision history
v1.0 2022-11-15 Initial release.
v1.1 2022-11-29 Updated with reference to FreeBSD-EN-22:28.heimdal.
For general information regarding FreeBSD Security Advisories,
including descrip
Red Hat
krb5: integer overflow vulnerabilities in PAC parsing
vendor_redhat·2022-11-15·CVSS 8.8
CVE-2022-42898 [HIGH] CWE-190 krb5: integer overflow vulnerabilities in PAC parsing
krb5: integer overflow vulnerabilities in PAC parsing
PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has "a similar bug."
A vulnerability was found in MIT krb5. This flaw allows an authenticated attacker to cause a KDC or kadmind process to crash by reading beyond the bounds of allocated memory, creating a denial of service. A privileged attacker may similarly be able to cause a Kerberos or GSS application service to crash.
Statement: Samba in
Debian
CVE-2022-42898: heimdal - PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 ...
vendor_debian·2022·CVSS 8.8
CVE-2022-42898 [HIGH] CVE-2022-42898: heimdal - PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 ...
PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has "a similar bug."
Scope: local
bookworm: resolved (fixed in 7.8.git20221115.a6cf945+dfsg-1)
bullseye: resolved (fixed in 7.7.0+dfsg-2+deb11u2)
forky: resolved (fixed in 7.8.git20221115.a6cf945+dfsg-1)
sid: resolved (fixed in 7.8.git20221115.a6cf945+dfsg-1)
trixie: resolved (fixed in 7.8.git20221115.a6cf945+dfsg-1)
OSV
samba regression
osv·2025-06-30·CVSS 6.5
CVE-2022-3437 [MEDIUM] samba regression
samba regression
USN-7582-1 fixed vulnerabilities in Samba. The update introduced a
regression. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Evgeny Legerov discovered that Samba incorrectly handled buffers in
certain GSSAPI routines of Heimdal. A remote attacker could possibly use
this issue to cause Samba to crash, resulting in a denial of service.
(CVE-2022-3437)
Greg Hudson discovered that Samba incorrectly handled PAC parsing. On
32-bit systems, a remote attacker could use this issue to escalate
privileges, or possibly execute arbitrary code. (CVE-2022-42898)
Joseph Sutton discovered that Samba could be forced to issue rc4-hmac
encrypted Kerberos tickets. A remote attacker could possibly use this
issue to escalate privileges. This
OSV
samba vulnerabilities
osv·2025-06-19·CVSS 6.5
CVE-2022-3437 [MEDIUM] samba vulnerabilities
samba vulnerabilities
Evgeny Legerov discovered that Samba incorrectly handled buffers in
certain GSSAPI routines of Heimdal. A remote attacker could possibly use
this issue to cause Samba to crash, resulting in a denial of service.
(CVE-2022-3437)
Greg Hudson discovered that Samba incorrectly handled PAC parsing. On
32-bit systems, a remote attacker could use this issue to escalate
privileges, or possibly execute arbitrary code. (CVE-2022-42898)
Joseph Sutton discovered that Samba could be forced to issue rc4-hmac
encrypted Kerberos tickets. A remote attacker could possibly use this issue
to escalate privileges. This issue only affected Ubuntu 20.04 LTS and
Ubuntu 22.04 LTS. (CVE-2022-45141)
Florent Saudel discovered that Samba incorrectly handled certain Spotlight
requests. A remote
OSV
samba vulnerabilities
osv·2023-03-08·CVSS 6.5
CVE-2022-3437 [MEDIUM] samba vulnerabilities
samba vulnerabilities
Evgeny Legerov discovered that Samba incorrectly handled buffers in
certain GSSAPI routines of Heimdal. A remote attacker could possibly use
this issue to cause Samba to crash, resulting in a denial of service.
(CVE-2022-3437)
Tom Tervoort discovered that Samba incorrectly used weak rc4-hmac Kerberos
keys. A remote attacker could possibly use this issue to elevate
privileges. (CVE-2022-37966, CVE-2022-37967)
It was discovered that Samba supported weak RC4/HMAC-MD5 in NetLogon Secure
Channel. A remote attacker could possibly use this issue to elevate
privileges. (CVE-2022-38023)
Greg Hudson discovered that Samba incorrectly handled PAC parsing. On
32-bit systems, a remote attacker could use this issue to escalate
privileges, or possibly execute arbitrary code. (CVE
OSV
samba regression
osv·2023-01-26·CVSS 5.9
[MEDIUM] samba regression
samba regression
USN-5822-1 fixed vulnerabilities in Samba. The update for Ubuntu 20.04 LTS
introduced regressions in certain environments. Pending investigation of
these regressions, this update temporarily reverts the security fixes.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Samba incorrectly handled the bad password count
logic. A remote attacker could possibly use this issue to bypass bad
passwords lockouts. This issue was only addressed in Ubuntu 22.10.
(CVE-2021-20251)
Evgeny Legerov discovered that Samba incorrectly handled buffers in
certain GSSAPI routines of Heimdal. A remote attacker could possibly use
this issue to cause Samba to crash, resulting in a denial of service.
(CVE-2022-3437)
Tom Tervoort discovered that Samba incorrec
OSV
krb5 vulnerabilities
osv·2023-01-25·CVSS 5.3
CVE-2018-20217 [MEDIUM] krb5 vulnerabilities
krb5 vulnerabilities
It was discovered that Kerberos incorrectly handled certain S4U2Self
requests. An attacker could possibly use this issue to cause a denial of
service. This issue was only addressed in Ubuntu 16.04 ESM and Ubuntu
18.04 LTS. (CVE-2018-20217)
Greg Hudson discovered that Kerberos PAC implementation incorrectly
handled certain parsing operations. A remote attacker could use this
issue to cause a denial of service, or possibly execute arbitrary code.
(CVE-2022-42898)
OSV
samba vulnerabilities
osv·2023-01-24·CVSS 5.9
CVE-2021-20251 [MEDIUM] samba vulnerabilities
samba vulnerabilities
It was discovered that Samba incorrectly handled the bad password count
logic. A remote attacker could possibly use this issue to bypass bad
passwords lockouts. This issue was only addressed in Ubuntu 22.10.
(CVE-2021-20251)
Evgeny Legerov discovered that Samba incorrectly handled buffers in
certain GSSAPI routines of Heimdal. A remote attacker could possibly use
this issue to cause Samba to crash, resulting in a denial of service.
(CVE-2022-3437)
Tom Tervoort discovered that Samba incorrectly used weak rc4-hmac Kerberos
keys. A remote attacker could possibly use this issue to elevate
privileges. (CVE-2022-37966, CVE-2022-37967)
It was discovered that Samba supported weak RC4/HMAC-MD5 in NetLogon Secure
Channel. A remote attacker could possibly use this issue to e
OSV
heimdal vulnerabilities
osv·2023-01-12·CVSS 7.5
CVE-2021-44758 [HIGH] heimdal vulnerabilities
heimdal vulnerabilities
It was discovered that Heimdal incorrectly handled certain SPNEGO tokens. A
remote attacker could possibly use this issue to cause a denial of service.
(CVE-2021-44758)
Evgeny Legerov discovered that Heimdal incorrectly handled memory when
performing certain DES decryption operations. A remote attacker could use
this issue to cause a denial of service, or possibly execute arbitrary
code. (CVE-2022-3437)
Greg Hudson discovered that Kerberos PAC implementation used in Heimdal
incorrectly handled certain parsing operations. A remote attacker could use
this issue to cause a denial of service, or possibly execute arbitrary
code. (CVE-2022-42898)
It was discovered that Heimdal's KDC did not properly handle certain error
conditions. A remote attacker could use this iss
OSV
CVE-2022-42898: PAC parsing in MIT Kerberos 5 (aka krb5) before 1
osv·2022-12-25·CVSS 8.8
CVE-2022-42898 [HIGH] CVE-2022-42898: PAC parsing in MIT Kerberos 5 (aka krb5) before 1
PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow), and cause a denial of service on other platforms. This occurs in krb5_pac_parse in lib/krb5/krb/pac.c. Heimdal before 7.7.1 has "a similar bug."
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.samba.org/show_bug.cgi?id=15203https://github.com/heimdal/heimdal/security/advisories/GHSA-64mq-fvfj-5x3chttps://github.com/krb5/krb5/commit/ea92d2f0fcceb54a70910fa32e9a0d7a5afc3583https://security.gentoo.org/glsa/202309-06https://security.gentoo.org/glsa/202310-06https://security.netapp.com/advisory/ntap-20230216-0008/https://security.netapp.com/advisory/ntap-20230223-0001/https://web.mit.edu/kerberos/advisories/https://web.mit.edu/kerberos/krb5-1.19/https://web.mit.edu/kerberos/krb5-1.20/README-1.20.1.txthttps://www.samba.org/samba/security/CVE-2022-42898.htmlhttps://bugzilla.samba.org/show_bug.cgi?id=15203https://github.com/heimdal/heimdal/security/advisories/GHSA-64mq-fvfj-5x3chttps://github.com/krb5/krb5/commit/ea92d2f0fcceb54a70910fa32e9a0d7a5afc3583https://security.gentoo.org/glsa/202309-06https://security.gentoo.org/glsa/202310-06https://security.netapp.com/advisory/ntap-20230216-0008/https://security.netapp.com/advisory/ntap-20230223-0001/https://web.mit.edu/kerberos/advisories/https://web.mit.edu/kerberos/krb5-1.19/https://web.mit.edu/kerberos/krb5-1.20/README-1.20.1.txthttps://www.samba.org/samba/security/CVE-2022-42898.html
2022-12-25
Published