Wind River Support Network

HomeDefectsLIN1018-10459
Fixed

LIN1018-10459 : Security Advisory - samba - CVE-2022-45142

Created: Mar 12, 2023    Updated: Apr 7, 2023
Resolved Date: Apr 7, 2023
Found In Version: 10.18.44.1
Fix Version: 10.18.44.29
Severity: Standard
Applicable for: Wind River Linux LTS 18
Component/s: Userspace

Description

The fix for CVE-2022-3437 included changing memcmp to be constant time and a workaround for a compiler bug by adding "!= 0" comparisons to the result of memcmp. When these patches were backported to the heimdal-7.7.1 and heimdal-7.8.0 branches (and possibly other branches) a logic inversion sneaked in causing the validation of message integrity codes in gssapi/arcfour to be inverted.

CREATE(Triage):(User=admin) CVE-2022-45142 (https://nvd.nist.gov/vuln/detail/CVE-2022-45142)

CVEs


Live chat
Online