First published: Thu Aug 25 2022(Updated: )
A flaw was found in Samba. Samba AD users can cause the server to access uninitialized data with an LDAP add or modify the request, usually resulting in a segmentation fault.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samba Samba | >=4.13.14<4.14.14 | |
Samba Samba | >=4.15.2<4.15.9 | |
Samba Samba | >=4.16.0<4.16.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-32745 is a vulnerability found in Samba that allows AD users to cause the server to access uninitialized data, leading to a segmentation fault.
CVE-2022-32745 affects Samba versions 4.13.14 to 4.14.14, 4.15.2 to 4.15.9, and 4.16.0 to 4.16.4.
CVE-2022-32745 has a severity rating of 8.1, which is considered high.
Samba AD users can exploit CVE-2022-32745 by sending an LDAP add or modify request that causes the server to access uninitialized data.
Yes, you can find references for CVE-2022-32745 at the following links: [https://security.gentoo.org/glsa/202309-06](https://security.gentoo.org/glsa/202309-06) and [https://www.samba.org/samba/security/CVE-2022-32745.html](https://www.samba.org/samba/security/CVE-2022-32745.html).