ALT-PU-2013-1099-1
Closed vulnerabilities
BDU:2021-01278
Уязвимость функции vfs_streams_depot or vfs_streams_xattr пакета программ сетевого взаимодействия Samba, позволяющая нарушителю получить доступ к конфиденциальным данным и нарушить их целостность
BDU:2021-01301
Уязвимость пакета программ сетевого взаимодействия Samba, связанная с недостатками в механизме криптографической защиты, позволяющая нарушителю получить доступ к конфиденциальным данным
Modified: 2024-11-21
CVE-2013-4475
Samba 3.2.x through 3.6.x before 3.6.20, 4.0.x before 4.0.11, and 4.1.x before 4.1.1, when vfs_streams_depot or vfs_streams_xattr is enabled, allows remote attackers to bypass intended file restrictions by leveraging ACL differences between a file and an associated alternate data stream (ADS).
- FEDORA-2014-9132
- FEDORA-2014-9132
- SUSE-SU-2014:0024
- SUSE-SU-2014:0024
- openSUSE-SU-2013:1742
- openSUSE-SU-2013:1742
- openSUSE-SU-2013:1787
- openSUSE-SU-2013:1787
- openSUSE-SU-2013:1790
- openSUSE-SU-2013:1790
- openSUSE-SU-2013:1921
- openSUSE-SU-2013:1921
- RHSA-2013:1806
- RHSA-2013:1806
- RHSA-2014:0009
- RHSA-2014:0009
- 56508
- 56508
- GLSA-201502-15
- GLSA-201502-15
- DSA-2812
- DSA-2812
- http://www.samba.org/samba/history/samba-3.6.20.html
- http://www.samba.org/samba/history/samba-3.6.20.html
- http://www.samba.org/samba/history/samba-4.0.11.html
- http://www.samba.org/samba/history/samba-4.0.11.html
- http://www.samba.org/samba/history/samba-4.1.1.html
- http://www.samba.org/samba/history/samba-4.1.1.html
- http://www.samba.org/samba/security/CVE-2013-4475
- http://www.samba.org/samba/security/CVE-2013-4475
- 63646
- 63646
- USN-2054-1
- USN-2054-1
- https://blogs.oracle.com/sunsecurity/entry/cve_2013_4475_access_control
- https://blogs.oracle.com/sunsecurity/entry/cve_2013_4475_access_control
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05115993
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05115993
Modified: 2024-11-21
CVE-2013-4476
Samba 4.0.x before 4.0.11 and 4.1.x before 4.1.1, when LDAP or HTTP is provided over SSL, uses world-readable permissions for a private key, which allows local users to obtain sensitive information by reading the key file, as demonstrated by access to the local filesystem on an AD domain controller.
- openSUSE-SU-2013:1742
- openSUSE-SU-2013:1742
- openSUSE-SU-2013:1921
- openSUSE-SU-2013:1921
- GLSA-201502-15
- GLSA-201502-15
- http://www.samba.org/samba/history/samba-4.0.11.html
- http://www.samba.org/samba/history/samba-4.0.11.html
- http://www.samba.org/samba/history/samba-4.1.1.html
- http://www.samba.org/samba/history/samba-4.1.1.html
- http://www.samba.org/samba/security/CVE-2013-4476
- http://www.samba.org/samba/security/CVE-2013-4476