Description
A null pointer de-reference was found in the way samba kerberos server handled missing sname in TGS-REQ (Ticket Granting Server - Request). An authenticated user could use this flaw to crash the samba server.
Related CPE's
a
samba
samba
o
debian
debian_linux
References
https://github.com/heimdal/heimdal/commit/04171147948d0a3636bc6374181926f0fb2ec83a
https://lists.debian.org/debian-lts-announce/2022/11/msg00034.html
https://security.netapp.com/advisory/ntap-20221215-0002/
https://security.netapp.com/advisory/ntap-20230216-0008/
https://www.debian.org/security/2022/dsa-5287
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
6.5 · Medium
CVSS V3.1
CVSS V3.0
CVSS V2.0
Information
Source identifier
Vulnerability status
Modified
Published
2021-10-12T18:15:08.357
3 years agoLast modified
2023-11-07T03:38:11.730
1 year ago