Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2022-2127
Description:An out-of-bounds read vulnerability was found in Samba due to insufficient length checks in winbindd_pam_auth_crap.c. When performing NTLM authentication, the client replies to cryptographic challenges back to the server. These replies have variable lengths, and Winbind fails to check the lan manager response length. When Winbind is used for NTLM authentication, a maliciously crafted request can trigger an out-of-bounds read in Winbind, possibly resulting in a crash.
Test IDs: 1.3.6.1.4.1.25623.1.1.4.2023.2887.1   1.3.6.1.4.1.25623.1.1.4.2023.3017.1   1.3.6.1.4.1.25623.1.0.833583   1.3.6.1.4.1.25623.1.1.4.2023.3358.1  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2022-2127
RHBZ#2222791
https://bugzilla.redhat.com/show_bug.cgi?id=2222791
RHSA-2023:6667
https://access.redhat.com/errata/RHSA-2023:6667
RHSA-2023:7139
https://access.redhat.com/errata/RHSA-2023:7139
RHSA-2024:0423
https://access.redhat.com/errata/RHSA-2024:0423
RHSA-2024:0580
https://access.redhat.com/errata/RHSA-2024:0580
https://access.redhat.com/security/cve/CVE-2022-2127
https://access.redhat.com/security/cve/CVE-2022-2127
https://lists.debian.org/debian-lts-announce/2024/04/msg00015.html
https://lists.debian.org/debian-lts-announce/2024/04/msg00015.html
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BPCSGND7LO467AJGR5DYBGZLTCGTOBCC/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BPCSGND7LO467AJGR5DYBGZLTCGTOBCC/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OT74M42E6C36W7PQVY3OS4ZM7DVYB64Z/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OT74M42E6C36W7PQVY3OS4ZM7DVYB64Z/
https://security.netapp.com/advisory/ntap-20230731-0010/
https://security.netapp.com/advisory/ntap-20230731-0010/
https://www.debian.org/security/2023/dsa-5477
https://www.debian.org/security/2023/dsa-5477
https://www.samba.org/samba/security/CVE-2022-2127.html
https://www.samba.org/samba/security/CVE-2022-2127.html




© 1998-2025 E-Soft Inc. All rights reserved.