Permissions, Privileges, and Access Controls in Samba - CVE-2013-6442
Published: March 14, 2014 / Updated: July 28, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
The owner_set function in smbcacls.c in smbcacls in Samba 4.0.x before 4.0.16 and 4.1.x before 4.1.6 removes an ACL during use of a --chown or --chgrp option, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging an unintended administrative change.
Affected software
samba (Alpine package)
Slackware Linux
How to mitigate CVE-2013-6442
samba (Alpine package) - update to 4.1.3-r1
External References
- http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136864.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-June/134717.html
- http://lists.opensuse.org/opensuse-updates/2014-03/msg00062.html
- http://www.samba.org/samba/history/samba-4.0.16.html
- http://www.samba.org/samba/history/samba-4.1.6.html
- http://www.samba.org/samba/security/CVE-2013-6442
- http://www.securityfocus.com/bid/66232
- https://bugzilla.samba.org/show_bug.cgi?id=10327