CVE-2022-32744
- EPSS 0.31%
- Veröffentlicht 25.08.2022 18:15:10
- Zuletzt bearbeitet 21.11.2024 07:06:52
A flaw was found in Samba. The KDC accepts kpasswd requests encrypted with any key known to it. By encrypting forged kpasswd requests with its own key, a user can change other users' passwords, enabling full domain takeover.
CVE-2022-32745
- EPSS 0.36%
- Veröffentlicht 25.08.2022 18:15:10
- Zuletzt bearbeitet 21.11.2024 07:06:52
A flaw was found in Samba. Samba AD users can cause the server to access uninitialized data with an LDAP add or modify the request, usually resulting in a segmentation fault.
CVE-2022-32746
- EPSS 0.22%
- Veröffentlicht 25.08.2022 18:15:10
- Zuletzt bearbeitet 21.11.2024 07:06:52
A flaw was found in the Samba AD LDAP server. The AD DC database audit logging module can access LDAP message values freed by a preceding database module, resulting in a use-after-free issue. This issue is only possible when modifying certain privile...
CVE-2022-2031
- EPSS 0.31%
- Veröffentlicht 25.08.2022 18:15:09
- Zuletzt bearbeitet 21.11.2024 07:00:12
A flaw was found in Samba. The security vulnerability occurs when KDC and the kpasswd service share a single account and set of keys, allowing them to decrypt each other's tickets. A user who has been requested to change their password, can exploit t...
CVE-2021-20316
- EPSS 0.44%
- Veröffentlicht 23.08.2022 16:15:09
- Zuletzt bearbeitet 21.11.2024 05:46:21
A flaw was found in the way Samba handled file/directory metadata. This flaw allows an authenticated attacker with permissions to read or modify share metadata, to perform this operation outside of the share.
CVE-2021-3670
- EPSS 3.76%
- Veröffentlicht 23.08.2022 16:15:09
- Zuletzt bearbeitet 21.08.2025 17:57:42
MaxQueryDuration not honoured in Samba AD DC LDAP
CVE-2020-25721
- EPSS 0.19%
- Veröffentlicht 16.03.2022 15:15:09
- Zuletzt bearbeitet 21.11.2024 05:18:34
Kerberos acceptors need easy access to stable AD identifiers (eg objectSid). Samba as an AD DC now provides a way for Linux applications to obtain a reliable SID (and samAccountName) in issued tickets.
CVE-2021-3738
- EPSS 0.29%
- Veröffentlicht 02.03.2022 23:15:09
- Zuletzt bearbeitet 21.11.2024 06:22:17
In DCE/RPC it is possible to share the handles (cookies for resource state) between multiple connections via a mechanism called 'association groups'. These handles can reference connections to our sam.ldb database. However while the database was corr...
CVE-2021-23192
- EPSS 0.06%
- Veröffentlicht 02.03.2022 23:15:08
- Zuletzt bearbeitet 21.11.2024 05:51:21
A flaw was found in the way samba implemented DCE/RPC. If a client to a Samba server sent a very large DCE/RPC request, and chose to fragment it, an attacker could replace later fragments with their own data, bypassing the signature requirements.
CVE-2021-44141
- EPSS 0.31%
- Veröffentlicht 21.02.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:30:25
All versions of Samba prior to 4.15.5 are vulnerable to a malicious client using a server symlink to determine if a file or directory exists in an area of the server file system not exported under the share definition. SMB1 with unix extensions has t...