PT-2014-1430 · Samba+3 · Samba+3

Noel Power

·

Published

2014-03-14

·

Updated

2024-06-15

·

CVE-2013-6442

CVSS v2.0

8.3

High

VectorAV:A/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Samba versions 4.0.x through 4.0.15 Samba versions 4.1.x through 4.1.5
Description The issue exists in the owner set function in smbcacls.c in smbcacls due to the removal of an access control list when using the --chown or --chgrp options. This allows remote attackers to bypass intended access restrictions by leveraging an unintended administrative change. The vulnerability can lead to a breach of confidentiality, integrity, and availability of protected information.
Recommendations For Samba versions 4.0.x through 4.0.15, update to version 4.0.16 or later. For Samba versions 4.1.x through 4.1.5, update to version 4.1.6 or later. As a temporary workaround, consider restricting the use of the --chown and --chgrp options in smbcacls until a patch is available.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1308
BDU:2015-00389
BDU:2015-06049
BDU:2015-08932
CESA-2014_0383
CVE-2013-6442
ECHO-37BB-8A91-8334
OPENSUSE-SU-2024:10069-1
RHSA-2014:0383
RHSA-2014_0383

Affected Products

Alt Linux
Centos
Red Hat
Samba