{"schema_version":"1.7.2","id":"OESA-2022-2038","modified":"2022-11-04T11:04:30Z","published":"2022-11-04T11:04:30Z","upstream":["CVE-2022-3437"],"summary":"samba security update","details":"Samba is a suite of programs for Linux and Unix to interoperate with Windows.\r\n\r\nSecurity Fix(es):\r\n\r\nThe DES (for Samba 4.11 and earlier) and Triple-DES decryption routines in the Heimdal GSSAPI library allow a length-limited write buffer overflow on malloc() allocated memory when presented with a maliciously small packet.\r\n\r\nAffects - All versions of Samba since Samba 4.0 compiled with Heimdal Kerberos.\nSamba 4.15.11, 4.16.6 and 4.17.2 have been issued as security releases to correct the defect\r\n\r\nhttps://www.samba.org/samba/security/CVE-2022-3437.html(CVE-2022-3437)","affected":[{"package":{"ecosystem":"openEuler:20.03-LTS-SP1","name":"samba","purl":"pkg:rpm/openEuler/samba\u0026distro=openEuler-20.03-LTS-SP1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.11.12-20.oe1"}]}],"ecosystem_specific":{"aarch64":["samba-dc-4.11.12-20.oe1.aarch64.rpm","samba-debugsource-4.11.12-20.oe1.aarch64.rpm","python3-samba-test-4.11.12-20.oe1.aarch64.rpm","samba-krb5-printing-4.11.12-20.oe1.aarch64.rpm","samba-libs-4.11.12-20.oe1.aarch64.rpm","samba-dc-provision-4.11.12-20.oe1.aarch64.rpm","samba-winbind-krb5-locator-4.11.12-20.oe1.aarch64.rpm","samba-client-4.11.12-20.oe1.aarch64.rpm","ctdb-tests-4.11.12-20.oe1.aarch64.rpm","samba-test-4.11.12-20.oe1.aarch64.rpm","python3-samba-dc-4.11.12-20.oe1.aarch64.rpm","samba-4.11.12-20.oe1.aarch64.rpm","samba-winbind-clients-4.11.12-20.oe1.aarch64.rpm","samba-debuginfo-4.11.12-20.oe1.aarch64.rpm","samba-winbind-4.11.12-20.oe1.aarch64.rpm","samba-dc-bind-dlz-4.11.12-20.oe1.aarch64.rpm","samba-devel-4.11.12-20.oe1.aarch64.rpm","libsmbclient-4.11.12-20.oe1.aarch64.rpm","samba-winbind-modules-4.11.12-20.oe1.aarch64.rpm","samba-common-4.11.12-20.oe1.aarch64.rpm","samba-common-tools-4.11.12-20.oe1.aarch64.rpm","libwbclient-devel-4.11.12-20.oe1.aarch64.rpm","python3-samba-4.11.12-20.oe1.aarch64.rpm","libwbclient-4.11.12-20.oe1.aarch64.rpm","samba-help-4.11.12-20.oe1.aarch64.rpm","libsmbclient-devel-4.11.12-20.oe1.aarch64.rpm","ctdb-4.11.12-20.oe1.aarch64.rpm"],"noarch":["samba-pidl-4.11.12-20.oe1.noarch.rpm"],"src":["samba-4.11.12-20.oe1.src.rpm"],"x86_64":["samba-help-4.11.12-20.oe1.x86_64.rpm","samba-4.11.12-20.oe1.x86_64.rpm","samba-winbind-krb5-locator-4.11.12-20.oe1.x86_64.rpm","samba-winbind-4.11.12-20.oe1.x86_64.rpm","python3-samba-test-4.11.12-20.oe1.x86_64.rpm","samba-client-4.11.12-20.oe1.x86_64.rpm","samba-debugsource-4.11.12-20.oe1.x86_64.rpm","ctdb-tests-4.11.12-20.oe1.x86_64.rpm","samba-common-tools-4.11.12-20.oe1.x86_64.rpm","samba-winbind-clients-4.11.12-20.oe1.x86_64.rpm","samba-libs-4.11.12-20.oe1.x86_64.rpm","libwbclient-4.11.12-20.oe1.x86_64.rpm","samba-vfs-glusterfs-4.11.12-20.oe1.x86_64.rpm","ctdb-4.11.12-20.oe1.x86_64.rpm","libwbclient-devel-4.11.12-20.oe1.x86_64.rpm","libsmbclient-devel-4.11.12-20.oe1.x86_64.rpm","samba-dc-bind-dlz-4.11.12-20.oe1.x86_64.rpm","samba-common-4.11.12-20.oe1.x86_64.rpm","samba-winbind-modules-4.11.12-20.oe1.x86_64.rpm","samba-dc-provision-4.11.12-20.oe1.x86_64.rpm","samba-devel-4.11.12-20.oe1.x86_64.rpm","samba-krb5-printing-4.11.12-20.oe1.x86_64.rpm","samba-dc-4.11.12-20.oe1.x86_64.rpm","samba-test-4.11.12-20.oe1.x86_64.rpm","python3-samba-dc-4.11.12-20.oe1.x86_64.rpm","samba-debuginfo-4.11.12-20.oe1.x86_64.rpm","libsmbclient-4.11.12-20.oe1.x86_64.rpm","python3-samba-4.11.12-20.oe1.x86_64.rpm"]}},{"package":{"ecosystem":"openEuler:20.03-LTS-SP3","name":"samba","purl":"pkg:rpm/openEuler/samba\u0026distro=openEuler-20.03-LTS-SP3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.11.12-19.oe1"}]}],"ecosystem_specific":{"aarch64":["python3-samba-4.11.12-19.oe1.aarch64.rpm","samba-debugsource-4.11.12-19.oe1.aarch64.rpm","samba-winbind-modules-4.11.12-19.oe1.aarch64.rpm","samba-4.11.12-19.oe1.aarch64.rpm","ctdb-tests-4.11.12-19.oe1.aarch64.rpm","samba-libs-4.11.12-19.oe1.aarch64.rpm","samba-debuginfo-4.11.12-19.oe1.aarch64.rpm","samba-krb5-printing-4.11.12-19.oe1.aarch64.rpm","python3-samba-dc-4.11.12-19.oe1.aarch64.rpm","samba-dc-4.11.12-19.oe1.aarch64.rpm","samba-winbind-4.11.12-19.oe1.aarch64.rpm","samba-dc-bind-dlz-4.11.12-19.oe1.aarch64.rpm","samba-dc-provision-4.11.12-19.oe1.aarch64.rpm","samba-common-tools-4.11.12-19.oe1.aarch64.rpm","samba-winbind-krb5-locator-4.11.12-19.oe1.aarch64.rpm","samba-client-4.11.12-19.oe1.aarch64.rpm","samba-winbind-clients-4.11.12-19.oe1.aarch64.rpm","libwbclient-devel-4.11.12-19.oe1.aarch64.rpm","ctdb-4.11.12-19.oe1.aarch64.rpm","samba-help-4.11.12-19.oe1.aarch64.rpm","libsmbclient-4.11.12-19.oe1.aarch64.rpm","libwbclient-4.11.12-19.oe1.aarch64.rpm","python3-samba-test-4.11.12-19.oe1.aarch64.rpm","samba-test-4.11.12-19.oe1.aarch64.rpm","libsmbclient-devel-4.11.12-19.oe1.aarch64.rpm","samba-devel-4.11.12-19.oe1.aarch64.rpm","samba-common-4.11.12-19.oe1.aarch64.rpm"],"noarch":["samba-pidl-4.11.12-19.oe1.noarch.rpm"],"src":["samba-4.11.12-19.oe1.src.rpm"],"x86_64":["libsmbclient-4.11.12-19.oe1.x86_64.rpm","samba-help-4.11.12-19.oe1.x86_64.rpm","python3-samba-4.11.12-19.oe1.x86_64.rpm","samba-dc-provision-4.11.12-19.oe1.x86_64.rpm","samba-winbind-krb5-locator-4.11.12-19.oe1.x86_64.rpm","python3-samba-dc-4.11.12-19.oe1.x86_64.rpm","samba-client-4.11.12-19.oe1.x86_64.rpm","samba-libs-4.11.12-19.oe1.x86_64.rpm","python3-samba-test-4.11.12-19.oe1.x86_64.rpm","ctdb-4.11.12-19.oe1.x86_64.rpm","samba-debugsource-4.11.12-19.oe1.x86_64.rpm","samba-common-tools-4.11.12-19.oe1.x86_64.rpm","samba-dc-4.11.12-19.oe1.x86_64.rpm","samba-debuginfo-4.11.12-19.oe1.x86_64.rpm","libwbclient-4.11.12-19.oe1.x86_64.rpm","ctdb-tests-4.11.12-19.oe1.x86_64.rpm","libsmbclient-devel-4.11.12-19.oe1.x86_64.rpm","samba-devel-4.11.12-19.oe1.x86_64.rpm","samba-vfs-glusterfs-4.11.12-19.oe1.x86_64.rpm","samba-test-4.11.12-19.oe1.x86_64.rpm","samba-dc-bind-dlz-4.11.12-19.oe1.x86_64.rpm","samba-4.11.12-19.oe1.x86_64.rpm","samba-winbind-clients-4.11.12-19.oe1.x86_64.rpm","samba-krb5-printing-4.11.12-19.oe1.x86_64.rpm","libwbclient-devel-4.11.12-19.oe1.x86_64.rpm","samba-common-4.11.12-19.oe1.x86_64.rpm","samba-winbind-modules-4.11.12-19.oe1.x86_64.rpm","samba-winbind-4.11.12-19.oe1.x86_64.rpm"]}},{"package":{"ecosystem":"openEuler:22.03-LTS","name":"samba","purl":"pkg:rpm/openEuler/samba\u0026distro=openEuler-22.03-LTS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.15.3-12.oe2203"}]}],"ecosystem_specific":{"aarch64":["samba-winbind-clients-4.15.3-12.oe2203.aarch64.rpm","samba-common-4.15.3-12.oe2203.aarch64.rpm","samba-libs-4.15.3-12.oe2203.aarch64.rpm","samba-client-4.15.3-12.oe2203.aarch64.rpm","samba-debuginfo-4.15.3-12.oe2203.aarch64.rpm","samba-devel-4.15.3-12.oe2203.aarch64.rpm","python3-samba-test-4.15.3-12.oe2203.aarch64.rpm","samba-help-4.15.3-12.oe2203.aarch64.rpm","samba-dc-4.15.3-12.oe2203.aarch64.rpm","python3-samba-4.15.3-12.oe2203.aarch64.rpm","samba-winbind-krb5-locator-4.15.3-12.oe2203.aarch64.rpm","samba-dc-bind-dlz-4.15.3-12.oe2203.aarch64.rpm","libwbclient-devel-4.15.3-12.oe2203.aarch64.rpm","samba-4.15.3-12.oe2203.aarch64.rpm","samba-winbind-4.15.3-12.oe2203.aarch64.rpm","samba-krb5-printing-4.15.3-12.oe2203.aarch64.rpm","samba-debugsource-4.15.3-12.oe2203.aarch64.rpm","python3-samba-dc-4.15.3-12.oe2203.aarch64.rpm","libsmbclient-4.15.3-12.oe2203.aarch64.rpm","libwbclient-4.15.3-12.oe2203.aarch64.rpm","libsmbclient-devel-4.15.3-12.oe2203.aarch64.rpm","samba-winbind-modules-4.15.3-12.oe2203.aarch64.rpm","ctdb-4.15.3-12.oe2203.aarch64.rpm","samba-common-tools-4.15.3-12.oe2203.aarch64.rpm","samba-test-4.15.3-12.oe2203.aarch64.rpm","samba-dc-provision-4.15.3-12.oe2203.aarch64.rpm"],"noarch":["samba-pidl-4.15.3-12.oe2203.noarch.rpm"],"src":["samba-4.15.3-12.oe2203.src.rpm"],"x86_64":["samba-common-tools-4.15.3-12.oe2203.x86_64.rpm","samba-debuginfo-4.15.3-12.oe2203.x86_64.rpm","libwbclient-devel-4.15.3-12.oe2203.x86_64.rpm","samba-4.15.3-12.oe2203.x86_64.rpm","samba-test-4.15.3-12.oe2203.x86_64.rpm","python3-samba-test-4.15.3-12.oe2203.x86_64.rpm","samba-client-4.15.3-12.oe2203.x86_64.rpm","libsmbclient-devel-4.15.3-12.oe2203.x86_64.rpm","ctdb-4.15.3-12.oe2203.x86_64.rpm","libwbclient-4.15.3-12.oe2203.x86_64.rpm","python3-samba-dc-4.15.3-12.oe2203.x86_64.rpm","samba-dc-4.15.3-12.oe2203.x86_64.rpm","samba-winbind-clients-4.15.3-12.oe2203.x86_64.rpm","samba-vfs-glusterfs-4.15.3-12.oe2203.x86_64.rpm","libsmbclient-4.15.3-12.oe2203.x86_64.rpm","python3-samba-4.15.3-12.oe2203.x86_64.rpm","samba-krb5-printing-4.15.3-12.oe2203.x86_64.rpm","samba-winbind-krb5-locator-4.15.3-12.oe2203.x86_64.rpm","samba-help-4.15.3-12.oe2203.x86_64.rpm","samba-common-4.15.3-12.oe2203.x86_64.rpm","samba-libs-4.15.3-12.oe2203.x86_64.rpm","samba-devel-4.15.3-12.oe2203.x86_64.rpm","samba-dc-provision-4.15.3-12.oe2203.x86_64.rpm","samba-winbind-modules-4.15.3-12.oe2203.x86_64.rpm","samba-debugsource-4.15.3-12.oe2203.x86_64.rpm","samba-winbind-4.15.3-12.oe2203.x86_64.rpm","samba-dc-bind-dlz-4.15.3-12.oe2203.x86_64.rpm"]}}],"references":[{"type":"ADVISORY","url":"https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-2038"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-3437"}],"database_specific":{"severity":"Medium"}}