Critical Vulnerability in SMB patched now (CVE-2022-42898)
An open source Server Message Block (SMB) implementation for Linux and Unix systems, Samba can be used as an Active Directory Domain Controller (AD DC).
The Kerberos libraries used by Samba provide a mechanism for
authenticating a user or service by means of tickets that can contain
Privilege Attribute Certificates (PACs).
Both the Heimdal and MIT Kerberos libraries, and so the embedded
Heimdal shipped by Samba suffer from an integer multiplication
overflow when calculating how many bytes to allocate for a buffer for
the parsed PAC.
On a 32-bit system an overflow allows placement of 16-byte chunks of
entirely attacker- controlled data.
(Because the user's control over this calculation is limited to an
unsigned 32-bit value, 64-bit systems are not impacted).
The server most vulnerable is the KDC, as it will parse an
attacker-controlled PAC in the S4U2Proxy handler.
The secondary risk is to Kerberos-enabled file server installations in
a non-AD realm. A non-AD Heimdal KDC controlling such a realm may
pass on an attacker-controlled PAC within the service ticket.
Patches addressing these issues have been posted to:
https://www.samba.org/samba/security/
Additionally, Samba 4.15.12, 4.16.7, and 4.17.3 have been issued
as security releases to correct the defect. Samba administrators are
advised to upgrade to these releases or apply the patch as soon
as possible.
Subscribe to:
Post Comments (Atom)
Chinese Hackers Target US Treasury in Critical Cybersecurity Incident
Chinese Hackers Breach US Treasury in Major Cybersecurity Incident In a concerning cybersecurity breach, Chinese state-sponsored hackers g...
-
DigiCert's Revocation of 83,000 Certificates: A Critical Security Move DigiCert has begun the process of revoking over 83,000 SSL/TLS ...
-
The notorious Craxs Rat malware has recently unleashed its latest version, Update V5, introducing a range of new features and enhancements....
-
AWS Seizes Domains Used by Russian Threat Group APT29 in Credential-Stealing Campaign Amazon Web Services (AWS) has disrupted a phishing o...
No comments:
Post a Comment