CVE-2022-32746 -- samba vulnerabilityID: oval:org.secpod.oval:def:82406 | Date: (C)2022-07-29 (M)2024-01-02 |
Class: VULNERABILITY | Family: unix |
Samba AD users can induce a use-after-free in the server process with an LDAP add or modify request. The AD DC database audit logging module can be made to access LDAP message values that have been freed by a preceding database module, resulting in a use-after- free. This is only possible when modifying certain privileged attributes, such as userAccountControl.
Platform: |
Ubuntu 20.04 |
Ubuntu 22.04 |
Product: |
samba |
libldb1 |
libldb2 |