CVE-2011-2522
Last modified
CVE-2011-2522 is a vulnerability of currently unknown severity. Multiple cross-site request forgery (CSRF) vulnerabilities in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allow remote attackers to hijack the authentication of administrators for requests that (1) shut down daemons, (2) start daemons, (3) add shares, (4) remove shares, (5) add printers, (6) remove printers, (7) add user accounts, or (8) remove user accounts, as demonstrated by certain start, stop, and restart parameters to the status program.. EPSS estimates a 10.05% chance of exploitation in the next 30 days.
Description
Multiple cross-site request forgery (CSRF) vulnerabilities in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allow remote attackers to hijack the authentication of administrators for requests that (1) shut down daemons, (2) start daemons, (3) add shares, (4) remove shares, (5) add printers, (6) remove printers, (7) add user accounts, or (8) remove user accounts, as demonstrated by certain start, stop, and restart parameters to the status program.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Samba | Samba | >= 3.0.0, < 3.3.16 |
| Samba | Samba | >= 3.4.0, < 3.4.14 |
| Samba | Samba | >= 3.5.0, < 3.5.10 |
| Debian | Debian Linux | 5.0 |
| Debian | Debian Linux | 6.0 |
| Debian | Debian Linux | 7.0 |
| Canonical | Ubuntu Linux | 8.04 |
| Canonical | Ubuntu Linux | 10.04 |
| Canonical | Ubuntu Linux | 10.10 |
| Canonical | Ubuntu Linux | 11.04 |
References
- http://jvn.jp/en/jp/JVN29529126/index.htmlThird Party Advisory
- http://marc.info/?l=bugtraq&m=133527864025056&w=2Mailing List, Third Party Advisory
- http://osvdb.org/74071Broken Link
- http://samba.org/samba/history/samba-3.5.10.htmlVendor Advisory
- http://secunia.com/advisories/45393Third Party Advisory
- http://secunia.com/advisories/45488Third Party Advisory
- http://secunia.com/advisories/45496Third Party Advisory
- http://securityreason.com/securityalert/8317Third Party Advisory
- http://securitytracker.com/id?1025852Third Party Advisory, VDB Entry
- http://ubuntu.com/usn/usn-1182-1Third Party Advisory
- http://www.debian.org/security/2011/dsa-2290Third Party Advisory
- http://www.exploit-db.com/exploits/17577Exploit, Third Party Advisory, VDB Entry
- http://www.samba.org/samba/security/CVE-2011-2522Vendor Advisory
- http://www.securityfocus.com/bid/48899Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=721348Issue Tracking, Patch, Third Party Advisory
- https://bugzilla.samba.org/show_bug.cgi?id=8290Issue Tracking, Patch, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/68843Third Party Advisory, VDB Entry
- http://jvn.jp/en/jp/JVN29529126/index.htmlThird Party Advisory
- http://marc.info/?l=bugtraq&m=133527864025056&w=2Mailing List, Third Party Advisory
- http://osvdb.org/74071Broken Link
- http://samba.org/samba/history/samba-3.5.10.htmlVendor Advisory
- http://secunia.com/advisories/45393Third Party Advisory
- http://secunia.com/advisories/45488Third Party Advisory
- http://secunia.com/advisories/45496Third Party Advisory
- http://securityreason.com/securityalert/8317Third Party Advisory
- http://securitytracker.com/id?1025852Third Party Advisory, VDB Entry
- http://ubuntu.com/usn/usn-1182-1Third Party Advisory
- http://www.debian.org/security/2011/dsa-2290Third Party Advisory
- http://www.exploit-db.com/exploits/17577Exploit, Third Party Advisory, VDB Entry
- http://www.samba.org/samba/security/CVE-2011-2522Vendor Advisory
- http://www.securityfocus.com/bid/48899Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=721348Issue Tracking, Patch, Third Party Advisory
- https://bugzilla.samba.org/show_bug.cgi?id=8290Issue Tracking, Patch, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/68843Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2011-2522?
How severe is CVE-2011-2522?
How do I fix CVE-2011-2522?
Are you affected by CVE-2011-2522?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
