CVE Vulnerabilities

CVE-2013-4475

Published: Nov 13, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:H/Au:N/C:P/I:P/A:N
RedHat/V2
4.1 MODERATE
AV:A/AC:L/Au:S/C:P/I:P/A:N
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

Samba 3.2.x through 3.6.x before 3.6.20, 4.0.x before 4.0.11, and 4.1.x before 4.1.1, when vfs_streams_depot or vfs_streams_xattr is enabled, allows remote attackers to bypass intended file restrictions by leveraging ACL differences between a file and an associated alternate data stream (ADS).

Affected Software

NameVendorStart VersionEnd Version
SambaSamba3.2.0 (including)3.6.20 (excluding)
SambaSamba4.0.0 (including)4.0.11 (excluding)
SambaSamba4.1.0 (including)4.1.0 (including)
Red Hat Enterprise Linux 5RedHatsamba3x-0:3.6.6-0.138.el5_10*
Red Hat Enterprise Linux 6RedHatsamba-0:3.6.9-167.el6_5*
Red Hat Storage 2.1RedHatsamba-0:3.6.9-167.5.1.el6rhs*
SambaUbuntudevel*
SambaUbuntuesm-infra-legacy/trusty*
SambaUbuntuesm-infra/xenial*
SambaUbuntulucid*
SambaUbuntuprecise*
SambaUbuntuquantal*
SambaUbunturaring*
SambaUbuntusaucy*
SambaUbuntutrusty*
SambaUbuntutrusty/esm*
SambaUbuntuupstream*
SambaUbuntuutopic*
SambaUbuntuvivid*
SambaUbuntuwily*
SambaUbuntuxenial*
SambaUbuntuyakkety*
SambaUbuntuzesty*
Samba4Ubuntulucid*
Samba4Ubuntuprecise*
Samba4Ubuntuquantal*
Samba4Ubunturaring*
Samba4Ubuntusaucy*
Samba4Ubuntuupstream*

References