CVE-2013-6442
14.03.2014, 10:55
The owner_set function in smbcacls.c in smbcacls in Samba 4.0.x before 4.0.16 and 4.1.x before 4.1.6 removes an ACL during use of a --chown or --chgrp option, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging an unintended administrative change.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| samba | samba | 4.1.0 |
| samba | samba | 4.1.1 |
| samba | samba | 4.1.2 |
| samba | samba | 4.1.3 |
| samba | samba | 4.1.4 |
| samba | samba | 4.1.5 |
| samba | samba | 4.0.0 |
| samba | samba | 4.0.1 |
| samba | samba | 4.0.2 |
| samba | samba | 4.0.3 |
| samba | samba | 4.0.4 |
| samba | samba | 4.0.5 |
| samba | samba | 4.0.6 |
| samba | samba | 4.0.7 |
| samba | samba | 4.0.8 |
| samba | samba | 4.0.9 |
| samba | samba | 4.0.10 |
| samba | samba | 4.0.11 |
| samba | samba | 4.0.12 |
| samba | samba | 4.0.13 |
| samba | samba | 4.0.14 |
| samba | samba | 4.0.15 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| samba |
| ||||||||||||||||||||||
| samba4 |
|
Red Hat Enterprise Linux Releases
Red Hat Product | |||
|---|---|---|---|
| samba4 |
| ||
| samba4-client |
| ||
| samba4-common |
| ||
| samba4-dc |
| ||
| samba4-dc-libs |
| ||
| samba4-devel |
| ||
| samba4-libs |
| ||
| samba4-pidl |
| ||
| samba4-python |
| ||
| samba4-swat |
| ||
| samba4-test |
| ||
| samba4-winbind |
| ||
| samba4-winbind-clients |
| ||
| samba4-winbind-krb5-locator |
|
Common Weakness Enumeration
References