Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-32743

Опубликовано: 24 авг. 2022
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Samba does not validate the Validated-DNS-Host-Name right for the dNSHostName attribute which could permit unprivileged users to write it.

A flaw was found in samba that validates the domain name system's host name. This issue links a trailing $ to objectclass=computer, which helps avoid the creation of SPN values that collide with other, possibly privileged hosts.

Отчет

This security issue only affects the Samba Active Directory support. We do not ship this in RHEL; thus, it is not affected.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7sambaOut of support scope
Red Hat Enterprise Linux 8sambaNot affected
Red Hat Enterprise Linux 9sambaNot affected
Red Hat Storage 3sambaUnder investigation

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-276
https://bugzilla.redhat.com/show_bug.cgi?id=2121128samba: Validated dnsHostname write right needs to be implemented

EPSS

Процентиль: 74%
0.00851
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 3 лет назад

Samba does not validate the Validated-DNS-Host-Name right for the dNSHostName attribute which could permit unprivileged users to write it.

CVSS3: 7.5
nvd
больше 3 лет назад

Samba does not validate the Validated-DNS-Host-Name right for the dNSHostName attribute which could permit unprivileged users to write it.

CVSS3: 7.5
msrc
4 месяца назад

Samba does not validate the Validated-DNS-Host-Name right for the dNSHostName attribute which could permit unprivileged users to write it.

CVSS3: 7.5
debian
больше 3 лет назад

Samba does not validate the Validated-DNS-Host-Name right for the dNSH ...

CVSS3: 7.5
github
больше 3 лет назад

Samba does not validate the Validated-DNS-Host-Name right for the dNSHostName attribute which could permit unprivileged users to write it.

EPSS

Процентиль: 74%
0.00851
Низкий

7.5 High

CVSS3