First published: Thu Aug 25 2022(Updated: )
A flaw was found in Samba. The security vulnerability occurs when KDC and the kpasswd service share a single account and set of keys, allowing them to decrypt each other's tickets. A user who has been requested to change their password, can exploit this flaw to obtain and use tickets to other services.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samba Samba | <4.14.14 | |
Samba Samba | >=4.15.0<4.15.9 | |
Samba Samba | >=4.16.0<4.16.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-2031 is a security vulnerability in Samba that allows a user to obtain and use tickets to other services when the KDC and kpasswd service share a single account and set of keys.
The severity of CVE-2022-2031 is high, with a CVSS score of 8.8.
Samba versions up to and including 4.16.4 are affected by CVE-2022-2031.
A user who has been requested to change their password can exploit the CVE-2022-2031 vulnerability to obtain and use tickets to other services.
Yes, you can find more information about CVE-2022-2031 at the following references: - [Gentoo Security Advisory](https://security.gentoo.org/glsa/202309-06) - [Samba Security Advisory](https://www.samba.org/samba/security/CVE-2022-2031.html)