Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.150744
Category:General
Title:Samba >= 3.2.0 Bypass File Restriction Vulnerability (CVE-2013-4475)
Summary:ACLs are not checked on opening an alternate data stream on a; file or directory.
Description:Summary:
ACLs are not checked on opening an alternate data stream on a
file or directory.

Vulnerability Insight:
Samba versions 3.2.0 and above (all versions of 3.2.x, 3.3.x,
3.4.x, 3.5.x, 3.6.x, 4.0.x and 4.1.x) do not check the underlying
file or directory ACL when opening an alternate data stream.

According to the SMB1 and SMB2+ protocols the ACL on an underlying
file or directory should control what access is allowed to alternate
data streams that are associated with the file or directory.

By default no version of Samba supports alternate data streams
on files or directories.

Samba can be configured to support alternate data streams by loading
either one of two virtual file system modules (VFS) vfs_streams_depot or
vfs_streams_xattr supplied with Samba, so this bug only affects Samba
servers configured this way.

To determine if your server is vulnerable, check for the strings
'streams_depot' or 'streams_xattr' inside your smb.conf configuration
file.

Affected Software/OS:
Samba versions 3.2.0 through 3.6.19, 4.0.0 through 4.0.10 and
4.1.0.

Solution:
Update to version 3.6.20, 4.0.11, 4.1.1 or later.

CVSS Score:
4.0

CVSS Vector:
AV:N/AC:H/Au:N/C:P/I:P/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2013-4475
BugTraq ID: 63646
http://www.securityfocus.com/bid/63646
Debian Security Information: DSA-2812 (Google Search)
http://www.debian.org/security/2013/dsa-2812
http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136864.html
http://security.gentoo.org/glsa/glsa-201502-15.xml
RedHat Security Advisories: RHSA-2013:1806
http://rhn.redhat.com/errata/RHSA-2013-1806.html
RedHat Security Advisories: RHSA-2014:0009
http://rhn.redhat.com/errata/RHSA-2014-0009.html
http://secunia.com/advisories/56508
SuSE Security Announcement: SUSE-SU-2014:0024 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2014-01/msg00002.html
SuSE Security Announcement: openSUSE-SU-2013:1742 (Google Search)
http://lists.opensuse.org/opensuse-updates/2013-11/msg00083.html
SuSE Security Announcement: openSUSE-SU-2013:1787 (Google Search)
http://lists.opensuse.org/opensuse-updates/2013-11/msg00115.html
SuSE Security Announcement: openSUSE-SU-2013:1790 (Google Search)
http://lists.opensuse.org/opensuse-updates/2013-11/msg00117.html
SuSE Security Announcement: openSUSE-SU-2013:1921 (Google Search)
http://lists.opensuse.org/opensuse-updates/2013-12/msg00088.html
http://www.ubuntu.com/usn/USN-2054-1
CopyrightCopyright (C) 2021 Greenbone Networks GmbH

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.