PT-2013-1325 · Samba+1 · Samba+1

Björn Baumbach

+1

·

Published

2013-11-12

·

Updated

2024-06-15

·

CVE-2013-4476

CVSS v2.0

1.2

Low

VectorAV:L/AC:H/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Samba versions 4.0.x through 4.0.10 Samba versions 4.1.x through 4.1.0
Description The issue is related to insufficient cryptographic protection mechanisms in Samba, allowing local users to obtain sensitive information. When LDAP or HTTP is provided over SSL, Samba uses world-readable permissions for a private key, enabling access to the key file and potentially allowing attackers to obtain confidential data.
Recommendations For Samba versions 4.0.x through 4.0.10, update to version 4.0.11 or later. For Samba versions 4.1.x through 4.1.0, update to version 4.1.1 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2013-1099
BDU:2021-01301
CVE-2013-4476
ECHO-A71F-6E74-B0F4
OPENSUSE-SU-2024:10069-1

Affected Products

Alt Linux
Samba