CVE-2022-32742

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
25/08/2022
Last modified:
03/07/2024

Description

A flaw was found in Samba. Some SMB1 write requests were not correctly range-checked to ensure the client had sent enough data to fulfill the write, allowing server memory contents to be written into the file (or printer) instead of client-supplied data. The client cannot control the area of the server memory written to the file (or printer).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* 4.14.14 (excluding)
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* 4.15.0 (including) 4.15.9 (excluding)
cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* 4.16.0 (including) 4.16.4 (excluding)