PT-2011-1099 · Samba Team+2 · Samba+2
Yoshihiro Ishikawa
·
Published
2011-07-29
·
Updated
2024-06-15
·
CVE-2011-2522
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Samba versions 3.5.6
Samba versions prior to 3.5.10
cifs-utils version 4.8.1
Description
The issue concerns multiple vulnerabilities in the Samba software package, which can lead to a breach of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. Specifically, the Samba Web Administration Tool (SWAT) in Samba 3.x is affected by multiple cross-site request forgery (CSRF) vulnerabilities, allowing remote attackers to hijack the authentication of administrators for various requests, such as shutting down daemons, starting daemons, adding shares, removing shares, adding printers, removing printers, adding user accounts, or removing user accounts.
Recommendations
For Samba versions 3.5.6, consider updating to a version prior to 3.5.10 to mitigate the risk.
For cifs-utils version 4.8.1, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, consider restricting access to the Samba Web Administration Tool (SWAT) to minimize the risk of exploitation.
Avoid using the Samba software package until the issue is resolved.
Exploit
CSRF
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Red Hat
Samba
Cifs-Utils