CVE-2013-4475

Samba 3.2.x-3.6.x - Unauthenticated File Restriction Bypass via Alternate Data Stream ACL Handling

Title source: llm
STIX 2.1

Description

Samba 3.2.x through 3.6.x before 3.6.20, 4.0.x before 4.0.11, and 4.1.x before 4.1.1, when vfs_streams_depot or vfs_streams_xattr is enabled, allows remote attackers to bypass intended file restrictions by leveraging ACL differences between a file and an associated alternate data stream (ADS).

References (19)

Core 19
Core References
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2054-1
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136864.html
Vendor Advisory x_refsource_confirm
http://www.samba.org/samba/history/samba-4.1.1.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/56508
Vendor Advisory x_refsource_confirm
http://www.samba.org/samba/history/samba-4.0.11.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/63646
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2013/dsa-2812
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2014-01/msg00002.html
Vendor Advisory x_refsource_confirm
http://www.samba.org/samba/history/samba-3.6.20.html
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-201502-15.xml
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2013-11/msg00083.html
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2013-12/msg00088.html
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2013-11/msg00115.html
Vendor Advisory x_refsource_confirm
http://www.samba.org/samba/security/CVE-2013-4475
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-1806.html
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2013-11/msg00117.html
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2014-0009.html

Scores

EPSS 0.0690
EPSS Percentile 91.5%

Details

CWE
CWE-264
Status published
Products (9)
canonical/ubuntu_linux 10.04
canonical/ubuntu_linux 12.04
canonical/ubuntu_linux 12.10
canonical/ubuntu_linux 13.04
canonical/ubuntu_linux 13.10
debian/debian_linux 6.0
debian/debian_linux 7.0
samba/samba 4.1.0
samba/samba 3.2.0 - 3.6.20
Published Nov 13, 2013
Tracked Since Feb 18, 2026