Vulnerability CVE-2013-0454


Published: 2013-03-26   Modified: 2013-03-27

Description:
The SMB2 implementation in Samba 3.6.x before 3.6.6, as used on the IBM Storwize V7000 Unified 1.3 before 1.3.2.3 and 1.4 before 1.4.0.1 and possibly other products, does not properly enforce CIFS share attributes, which allows remote authenticated users to (1) write to a read-only share; (2) trigger data-integrity problems related to the oplock, locking, coherency, or leases attribute; or (3) have an unspecified impact by leveraging incorrect handling of the browseable or "hide unreadable" parameter.

CVSS2 => (AV:N/AC:L/Au:S/C:N/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4/10
2.9/10
8/10
Exploit range
Attack complexity
Authentication
Remote
Low
Single time
Confidentiality impact
Integrity impact
Availability impact
None
Partial
None
Affected software
Samba -> Samba 
IBM -> Storwize 

 References:
https://www.samba.org/samba/security/CVE-2013-0454
https://lists.samba.org/archive/samba-announce/2012/000259.html
https://bugzilla.samba.org/show_bug.cgi?id=8738
https://bugzilla.redhat.com/show_bug.cgi?id=928419
http://xforce.iss.net/xforce/xfdb/80970
http://www.ubuntu.com/usn/USN-1802-1
http://www.ibm.com/support/docview.wss?uid=ssg1S1004289

Copyright 2024, cxsecurity.com

 

Back to Top