PT-2011-1100 · Samba+2 · Samba+2

Nobuhiro Tsuji

·

Published

2011-07-29

·

Updated

2024-06-15

·

CVE-2011-2694

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Samba versions 3.x through 3.5.9 Samba version 3.5.6
Description A cross-site scripting (XSS) vulnerability exists in the chg passwd function in the Samba Web Administration Tool (SWAT) due to the injection of arbitrary web script or HTML via the username parameter to the passwd program. This issue can be exploited remotely by authenticated administrators. Multiple vulnerabilities in Samba packages for Red Hat Enterprise Linux can lead to the disruption of confidentiality, integrity, and availability of protected information, and can be exploited remotely.
Recommendations For Samba versions 3.x through 3.5.9, update to version 3.5.10 or later to resolve the issue. For Samba version 3.5.6, consider disabling the chg passwd function in the SWAT tool as a temporary workaround until a patch is available. Restrict access to the Samba Web Administration Tool (SWAT) to minimize the risk of exploitation.

Fix

XSS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-06161
BDU:2015-06162
BDU:2015-06325
BDU:2015-06327
BDU:2015-06509
BDU:2015-06514
BDU:2015-06519
BDU:2015-06520
BDU:2015-06521
BDU:2015-06522
BDU:2015-06527
BDU:2015-06528
BDU:2015-06529
BDU:2015-06530
BDU:2015-06531
CVE-2011-2694
DSA-2290-1
ECHO-5FE7-FDF1-0CE6
OPENSUSE-SU-2024:10069-1
RHSA-2011:1219
RHSA-2011:1220
RHSA-2011:1221
RHSA-2011_1219
RHSA-2011_1220
RHSA-2011_1221

Affected Products

Red Hat
Samba
Suse