PT-2010-5673 · Samba+4 · Samba+4

Jann Horn

·

Published

1970-01-01

·

Updated

2024-06-15

·

CVE-2013-0214

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Samba versions 3.x through 3.5.20 Samba versions 3.6.x through 3.6.11 Samba versions 4.x through 4.0.1
Description A cross-site request forgery (CSRF) vulnerability in the Samba Web Administration Tool (SWAT) allows remote attackers to hijack the authentication of arbitrary users by leveraging knowledge of a password and composing requests that perform SWAT actions. Multiple vulnerabilities in Samba packages may lead to disruption of confidentiality, integrity, and availability of protected information, and can be exploited remotely.
Recommendations For Samba versions 3.x through 3.5.20, update to version 3.5.21 or later. For Samba versions 3.6.x through 3.6.11, update to version 3.6.12 or later. For Samba versions 4.x through 4.0.1, update to version 4.0.2 or later. As a temporary workaround, consider disabling the SWAT service until a patch is available. Restrict access to the Samba Web Administration Tool to minimize the risk of exploitation.

Fix

CSRF

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-04392
BDU:2015-04393
BDU:2015-06051
BDU:2015-06052
BDU:2015-06324
BDU:2015-06326
BDU:2015-06507
BDU:2015-06512
BDU:2015-06517
BDU:2015-06525
BDU:2015-08944
BDU:2015-08945
BDU:2015-08946
BDU:2015-08947
BDU:2015-08948
CESA-2013_1542
CVE-2013-0214
DSA-2617-1
ECHO-7E3A-FB5C-8ACE
OPENSUSE-SU-2024:10069-1
RHSA-2013:1310
RHSA-2013:1542
RHSA-2013_1310
RHSA-2013_1542
RHSA-2014:0305
RHSA-2014_0305
SUSE-SU-2015:0386-1
USN-2922-1

Affected Products

Centos
Red Hat
Samba
Suse
Ubuntu