First published: Thu Apr 28 2022(Updated: )
cifs-utils through 6.14, with verbose logging, can cause an information leak when a file contains = (equal sign) characters but is not a valid credentials file.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Samba Cifs-utils | <6.15 | |
Fedoraproject Fedora | =34 | |
Fedoraproject Fedora | =35 | |
Fedoraproject Fedora | =36 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 | |
Debian Debian Linux | =11.0 | |
debian/cifs-utils | 2:6.8-2+deb10u1 2:6.11-3.1+deb11u1 2:7.0-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-29869 is a vulnerability in cifs-utils through version 6.14 that can cause an information leak when a file contains = (equal sign) characters but is not a valid credentials file.
CVE-2022-29869 affects Samba Cifs-utils versions up to and excluding 6.15.
CVE-2022-29869 affects Fedora 34, Fedora 35, Fedora 36, Debian Linux 9.0, Debian Linux 10.0, and Debian Linux 11.0.
CVE-2022-29869 has a severity rating of 5.3 (Medium).
To fix CVE-2022-29869, update cifs-utils to version 2:6.8-2+deb10u1, 2:6.11-3.1+deb11u1, or 2:7.0-2.