PT-2014-1430 · Samba+3 · Samba+3

Noel Power

·

Publicado

2014-03-14

·

Atualizado

2024-06-15

·

CVE-2013-6442

CVSS v2.0

8.3

Alta

VetorAV:A/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Samba versions 4.0.x through 4.0.15 Samba versions 4.1.x through 4.1.5
Description The issue exists in the owner set function in smbcacls.c in smbcacls due to the removal of an access control list when using the --chown or --chgrp options. This allows remote attackers to bypass intended access restrictions by leveraging an unintended administrative change. The vulnerability can lead to a breach of confidentiality, integrity, and availability of protected information.
Recommendations For Samba versions 4.0.x through 4.0.15, update to version 4.0.16 or later. For Samba versions 4.1.x through 4.1.5, update to version 4.1.6 or later. As a temporary workaround, consider restricting the use of the --chown and --chgrp options in smbcacls until a patch is available.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2014-1308
BDU:2015-00389
BDU:2015-06049
BDU:2015-08932
CESA-2014_0383
CVE-2013-6442
ECHO-37BB-8A91-8334
OPENSUSE-SU-2024:10069-1
RHSA-2014:0383
RHSA-2014_0383

Produtos afetados

Alt Linux
Centos
Red Hat
Samba