PT-2013-1324 · Samba+4 · Samba+4

Hemanth Thummala

·

Publicado

2013-11-12

·

Atualizado

2024-06-15

·

CVE-2013-4475

CVSS v2.0

4.0

Média

VetorAV:N/AC:H/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Samba versions 3.2.x through 3.6.x before 3.6.20 Samba versions 4.0.x before 4.0.11 Samba versions 4.1.x before 4.1.1
Description The issue is related to a lack of privilege control and access management mechanisms in the vfs streams depot or vfs streams xattr functions of Samba network interaction programs. This can allow a remote attacker to bypass intended file restrictions by leveraging ACL differences between a file and an associated alternate data stream (ADS), potentially gaining access to confidential data and compromising its integrity.
Recommendations For Samba versions 3.2.x through 3.6.x before 3.6.20, update to version 3.6.20 or later. For Samba versions 4.0.x before 4.0.11, update to version 4.0.11 or later. For Samba versions 4.1.x before 4.1.1, update to version 4.1.1 or later. As a temporary workaround, consider disabling the vfs streams depot and vfs streams xattr functions until a patch is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2013-1099
BDU:2021-01278
CESA-2013_1806
CVE-2013-4475
DSA-2812-1
ECHO-B78D-D090-F185
MGASA-2013-0348
OPENSUSE-SU-2024:10069-1
RHSA-2013:1806
RHSA-2013_1806
RHSA-2014:0009
SUSE-SU-2014_0839-1
SUSE-SU-2015:0386-1
USN-2054-1

Produtos afetados

Alt Linux
Centos
Red Hat
Samba
Suse