Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.104258
Category:Denial of Service
Title:Samba DoS Vulnerability (CVE-2022-32745)
Summary:Samba is prone to a denial of service (DoS) vulnerability.
Description:Summary:
Samba is prone to a denial of service (DoS) vulnerability.

Vulnerability Insight:
Due to incorrect values used as the limit for a loop and as the
'count' parameter to memcpy(), the server, receiving a specially crafted message, leaves an array
of structures partially uninitialised, or accesses an arbitrary element beyond the end of an
array.

Outcomes achievable by an attacker include segmentation faults and corresponding loss of
availability. Depending on the contents of the uninitialised memory, confidentiality may also be
affected.

Affected Software/OS:
Samba versions 4.13.x starting from 4.13.14, 4.14.x starting
from 4.14.10 and prior to 4.14.14, 4.15.x starting from 4.15.2 and prior to 4.15.9, and 4.16.x
prior to 4.16.4.

Solution:
Update to version 4.14.14, 4.15.9, 4.16.4 or later.

CVSS Score:
9.4

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:N/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2022-32745
https://security.gentoo.org/glsa/202309-06
https://www.samba.org/samba/security/CVE-2022-32745.html
CopyrightCopyright (C) 2022 Greenbone Networks GmbH

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.