CVE Vulnerabilities

CVE-2013-4475

Published: Nov 13, 2013 | Modified: Sep 01, 2022
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:H/Au:N/C:P/I:P/A:N
RedHat/V2
4.1 MODERATE
AV:A/AC:L/Au:S/C:P/I:P/A:N
RedHat/V3
Ubuntu
LOW

Samba 3.2.x through 3.6.x before 3.6.20, 4.0.x before 4.0.11, and 4.1.x before 4.1.1, when vfs_streams_depot or vfs_streams_xattr is enabled, allows remote attackers to bypass intended file restrictions by leveraging ACL differences between a file and an associated alternate data stream (ADS).

Affected Software

Name Vendor Start Version End Version
Samba Samba 3.2.0 (including) 3.6.20 (excluding)
Samba Samba 4.0.0 (including) 4.0.11 (excluding)
Samba Samba 4.1.0 (including) 4.1.0 (including)
Red Hat Enterprise Linux 5 RedHat samba3x-0:3.6.6-0.138.el5_10 *
Red Hat Enterprise Linux 6 RedHat samba-0:3.6.9-167.el6_5 *
Red Hat Storage 2.1 RedHat samba-0:3.6.9-167.5.1.el6rhs *
Samba Ubuntu devel *
Samba Ubuntu lucid *
Samba Ubuntu precise *
Samba Ubuntu quantal *
Samba Ubuntu raring *
Samba Ubuntu saucy *
Samba Ubuntu trusty *
Samba Ubuntu upstream *
Samba Ubuntu utopic *
Samba Ubuntu vivid *
Samba Ubuntu wily *
Samba Ubuntu xenial *
Samba Ubuntu yakkety *
Samba Ubuntu zesty *
Samba4 Ubuntu lucid *
Samba4 Ubuntu precise *
Samba4 Ubuntu quantal *
Samba4 Ubuntu raring *
Samba4 Ubuntu saucy *
Samba4 Ubuntu upstream *

References