CVE-2022-29869

Description

cifs-utils through 6.14, with verbose logging, can cause an information leak when a file contains = (equal sign) characters but is not a valid credentials file.

Risk Information

Base Score
5.3
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Score
Exploitation Probability
0.854

Associated Vulnerability

VulnerabilityOS Platform
cifs-utils security update(DSA-5157-1) cifs-utils_6.8-2+deb10u1_i386.debLinux
cifs-utils security update(DSA-5157-1) cifs-utils_6.8-2+deb10u1_amd64.debLinux
cifs-utils security update(DSA-5157-1) cifs-utils_6.11-3.1+deb11u1_amd64.debLinux
Common Internet File System utilities (USN-5459-1) cifs-utils_6.8-1ubuntu1.2_i386.debLinux
Common Internet File System utilities (USN-5459-1) cifs-utils_6.8-1ubuntu1.2_amd64.debLinux
Common Internet File System utilities (USN-5459-1) cifs-utils_6.9-1ubuntu0.2_amd64.debLinux
Common Internet File System utilities (USN-5459-1) cifs-utils_6.14-1ubuntu0.1_i386.debLinux
Common Internet File System utilities (USN-5459-1) cifs-utils_6.14-1ubuntu0.1_amd64.debLinux
Common Internet File System utilities (USN-5459-1) cifs-utils_6.11-3.1ubuntu0.1_i386.debLinux
Common Internet File System utilities (USN-5459-1) cifs-utils_6.11-3.1ubuntu0.1_amd64.debLinux
SUSE-SU-2022:2802-1(SUSE Linux Enterprise Server 12-SP5 ) cifs-utils-6.9-13.23.1.x86_64.rpmLinux
SUSE-SU-2022:2802-1(SUSE Linux Enterprise Server 12-SP5 ) cifs-utils-debuginfo-6.9-13.23.1.x86_64.rpmLinux
SUSE-SU-2022:2802-1(SUSE Linux Enterprise Server 12-SP5 ) cifs-utils-debugsource-6.9-13.23.1.x86_64.rpmLinux
SUSE-SU-2022:2801-1(SUSE Linux Enterprise Module for Basesystem 15-SP3 ) cifs-utils-6.9-150100.5.18.1.x86_64.rpmLinux
SUSE-SU-2022:2801-1(SUSE Linux Enterprise Module for Basesystem 15-SP3 ) cifs-utils-devel-6.9-150100.5.18.1.x86_64.rpmLinux
cifs-utils security update(DSA-5157-1) cifs-utils_6.11-3.1+deb11u1_i386.debLinux
cifs-utils security update(DSA-5157-1) cifs-utils_6.11-3.1+deb11u2_i386.debLinux
cifs-utils security update(DSA-5157-1) cifs-utils_6.11-3.1+deb11u2_amd64.debLinux
cifs-utils Security Update (ALAS-2023-1977) cifs-utils-6.2-10.amzn2.0.4.x86_64.rpmLinux
cifs-utils Security Update (ALAS-2023-1977) cifs-utils-devel-6.2-10.amzn2.0.4.x86_64.rpmLinux
cifs-utils Security Update (ALAS-2024-530) cifs-utils-6.15-1.amzn2023.0.2.x86_64.rpmLinux
cifs-utils Security Update (ALAS-2024-530) pam_cifscreds-6.15-1.amzn2023.0.2.x86_64.rpmLinux
cifs-utils Security Update (ALAS-2024-530) cifs-utils-info-6.15-1.amzn2023.0.2.x86_64.rpmLinux
cifs-utils Security Update (ALAS-2024-530) cifs-utils-devel-6.15-1.amzn2023.0.2.x86_64.rpmLinux
cifs-utils Security Update (ALAS2-2023-1977) cifs-utils-6.2-10.amzn2.0.4.x86_64.rpmLinux
cifs-utils Security Update (ALAS2-2023-1977) cifs-utils-devel-6.2-10.amzn2.0.4.x86_64.rpmLinux
cifs-utils Security Update (ALAS2023-2024-530) pam_cifscreds-6.15-1.amzn2023.0.2.x86_64.rpmLinux
cifs-utils Security Update (ALAS2023-2024-530) cifs-utils-6.15-1.amzn2023.0.2.x86_64.rpmLinux
cifs-utils Security Update (ALAS2023-2024-530) cifs-utils-devel-6.15-1.amzn2023.0.2.x86_64.rpmLinux
cifs-utils Security Update (ALAS2023-2024-530) cifs-utils-info-6.15-1.amzn2023.0.2.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234