CVE-2013-0454
Last modified
CVE-2013-0454 is a vulnerability of currently unknown severity. The SMB2 implementation in Samba 3.6.x before 3.6.6, as used on the IBM Storwize V7000 Unified 1.3 before 1.3.2.3 and 1.4 before 1.4.0.1 and possibly other products, does not properly enforce CIFS share attributes, which allows remote authenticated users to (1) write to a read-only share; (2) trigger data-integrity problems related to the oplock, locking, coherency, or leases attribute; or (3) have an unspecified impact by leveraging incorrect handling of the browseable or "hide unreadable" parameter.. EPSS estimates a 2.98% chance of exploitation in the next 30 days.
Description
The SMB2 implementation in Samba 3.6.x before 3.6.6, as used on the IBM Storwize V7000 Unified 1.3 before 1.3.2.3 and 1.4 before 1.4.0.1 and possibly other products, does not properly enforce CIFS share attributes, which allows remote authenticated users to (1) write to a read-only share; (2) trigger data-integrity problems related to the oplock, locking, coherency, or leases attribute; or (3) have an unspecified impact by leveraging incorrect handling of the browseable or "hide unreadable" parameter.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Canonical | Ubuntu Linux | 12.04 | — |
| Samba | Samba | <= 3.6.5 | — |
| Samba | Samba | 3.6.0 | — |
| Samba | Samba | 3.6.1 | — |
| Samba | Samba | 3.6.2 | — |
| Samba | Samba | 3.6.3 | — |
| Samba | Samba | 3.6.4 | — |
| Ibm | Storwize | v7000 | 1.3 |
References
- http://www.ibm.com/support/docview.wss?uid=ssg1S1004289Vendor Advisory
- http://www.ubuntu.com/usn/USN-1802-1Vendor Advisory
- https://www.samba.org/samba/security/CVE-2013-0454Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=ssg1S1004289Vendor Advisory
- http://www.ubuntu.com/usn/USN-1802-1Vendor Advisory
- https://www.samba.org/samba/security/CVE-2013-0454Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-0454?
How severe is CVE-2013-0454?
How do I fix CVE-2013-0454?
Are you affected by CVE-2013-0454?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
