PT-2011-1100 · Samba+2 · Samba+2
Nobuhiro Tsuji
·
Publicado
2011-07-29
·
Atualizado
2024-06-15
·
CVE-2011-2694
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Samba versions 3.x through 3.5.9
Samba version 3.5.6
Description
A cross-site scripting (XSS) vulnerability exists in the chg passwd function in the Samba Web Administration Tool (SWAT) due to the injection of arbitrary web script or HTML via the
username parameter to the passwd program. This issue can be exploited remotely by authenticated administrators. Multiple vulnerabilities in Samba packages for Red Hat Enterprise Linux can lead to the disruption of confidentiality, integrity, and availability of protected information, and can be exploited remotely.Recommendations
For Samba versions 3.x through 3.5.9, update to version 3.5.10 or later to resolve the issue.
For Samba version 3.5.6, consider disabling the
chg passwd function in the SWAT tool as a temporary workaround until a patch is available.
Restrict access to the Samba Web Administration Tool (SWAT) to minimize the risk of exploitation.Correção
XSS
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Red Hat
Samba
Suse