CVE-2013-0454
published 2013-03-26CVE-2013-0454: The SMB2 implementation in Samba 3.6.x before 3.6.6, as used on the IBM Storwize V7000 Unified 1.3 before 1.3.2.3 and 1.4 before 1.4.0.1 and possibly other…
PriorityP420medium4CVSS 2.0
AVNACLAuSCNIPAN
EPSS
2.98%
85.9th percentile
The SMB2 implementation in Samba 3.6.x before 3.6.6, as used on the IBM Storwize V7000 Unified 1.3 before 1.3.2.3 and 1.4 before 1.4.0.1 and possibly other products, does not properly enforce CIFS share attributes, which allows remote authenticated users to (1) write to a read-only share; (2) trigger data-integrity problems related to the oplock, locking, coherency, or leases attribute; or (3) have an unspecified impact by leveraging incorrect handling of the browseable or "hide unreadable" parameter.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | samba | < samba 2:3.6.6-1 (bookworm) | samba 2:3.6.6-1 (bookworm) |
| ibm | storwize | — | — |
| samba | samba | <= 3.6.5 | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | >= 0 < 2:3.6.6-1 | 2:3.6.6-1 |
| samba | samba | >= 0 < 2:3.6.6-1 | 2:3.6.6-1 |
| samba | samba | >= 0 < 2:3.6.6-1 | 2:3.6.6-1 |
| samba | samba | >= 0 < 2:3.6.6-1 | 2:3.6.6-1 |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
osv4.0MEDIUM
vendor_debian4.0MEDIUM
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7f36-rv57-68gp: The SMB2 implementation in Samba 3
ghsa_unreviewed·2022-05-05
CVE-2013-0454 [MEDIUM] GHSA-7f36-rv57-68gp: The SMB2 implementation in Samba 3
The SMB2 implementation in Samba 3.6.x before 3.6.6, as used on the IBM Storwize V7000 Unified 1.3 before 1.3.2.3 and 1.4 before 1.4.0.1 and possibly other products, does not properly enforce CIFS share attributes, which allows remote authenticated users to (1) write to a read-only share; (2) trigger data-integrity problems related to the oplock, locking, coherency, or leases attribute; or (3) have an unspecified impact by leveraging incorrect handling of the browseable or "hide unreadable" parameter.
OSV
CVE-2013-0454: The SMB2 implementation in Samba 3
osv·2013-03-26·CVSS 4.0
CVE-2013-0454 [MEDIUM] CVE-2013-0454: The SMB2 implementation in Samba 3
The SMB2 implementation in Samba 3.6.x before 3.6.6, as used on the IBM Storwize V7000 Unified 1.3 before 1.3.2.3 and 1.4 before 1.4.0.1 and possibly other products, does not properly enforce CIFS share attributes, which allows remote authenticated users to (1) write to a read-only share; (2) trigger data-integrity problems related to the oplock, locking, coherency, or leases attribute; or (3) have an unspecified impact by leveraging incorrect handling of the browseable or "hide unreadable" parameter.
Ubuntu
Samba vulnerability
vendor_ubuntu·2013-04-16
CVE-2013-0454 Samba vulnerability
Title: Samba vulnerability
Summary: Samba would allow unintended write access to files over the network.
It was discovered that Samba incorrectly handled CIFS share attributes when
SMB2 was used. A remote authenticated user could possibly gain write access
to certain shares, bypassing the intended permissions.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2013-0454: samba - The SMB2 implementation in Samba 3.6.x before 3.6.6, as used on the IBM Storwize...
vendor_debian·2013·CVSS 4.0
CVE-2013-0454 [MEDIUM] CVE-2013-0454: samba - The SMB2 implementation in Samba 3.6.x before 3.6.6, as used on the IBM Storwize...
The SMB2 implementation in Samba 3.6.x before 3.6.6, as used on the IBM Storwize V7000 Unified 1.3 before 1.3.2.3 and 1.4 before 1.4.0.1 and possibly other products, does not properly enforce CIFS share attributes, which allows remote authenticated users to (1) write to a read-only share; (2) trigger data-integrity problems related to the oplock, locking, coherency, or leases attribute; or (3) have an unspecified impact by leveraging incorrect handling of the browseable or "hide unreadable" parameter.
Scope: local
bookworm: resolved (fixed in 2:3.6.6-1)
bullseye: resolved (fixed in 2:3.6.6-1)
forky: resolved (fixed in 2:3.6.6-1)
sid: resolved (fixed in 2:3.6.6-1)
trixie: resolved (fixed in 2:3.6.6-1)
Red Hat
samba: the SMB2 server does not release unused shares
vendor_redhat·2012-06-25·CVSS 4.0
CVE-2013-0454 [MEDIUM] samba: the SMB2 server does not release unused shares
samba: the SMB2 server does not release unused shares
The SMB2 implementation in Samba 3.6.x before 3.6.6, as used on the IBM Storwize V7000 Unified 1.3 before 1.3.2.3 and 1.4 before 1.4.0.1 and possibly other products, does not properly enforce CIFS share attributes, which allows remote authenticated users to (1) write to a read-only share; (2) trigger data-integrity problems related to the oplock, locking, coherency, or leases attribute; or (3) have an unspecified impact by leveraging incorrect handling of the browseable or "hide unreadable" parameter.
Statement: Not vulnerable. This issue did not affect the versions of samba as shipped with Red Hat Enterprise Linux 5 as they did not provide support for SMB2. This issue did not affect the versions of samba3x and samba as shipped with R
No detection rules found.
No public exploits indexed.
http://www.ibm.com/support/docview.wss?uid=ssg1S1004289http://www.ubuntu.com/usn/USN-1802-1https://bugzilla.redhat.com/show_bug.cgi?id=928419https://bugzilla.samba.org/show_bug.cgi?id=8738https://exchange.xforce.ibmcloud.com/vulnerabilities/80970https://lists.samba.org/archive/samba-announce/2012/000259.htmlhttps://www.samba.org/samba/security/CVE-2013-0454http://www.ibm.com/support/docview.wss?uid=ssg1S1004289http://www.ubuntu.com/usn/USN-1802-1https://bugzilla.redhat.com/show_bug.cgi?id=928419https://bugzilla.samba.org/show_bug.cgi?id=8738https://exchange.xforce.ibmcloud.com/vulnerabilities/80970https://lists.samba.org/archive/samba-announce/2012/000259.htmlhttps://www.samba.org/samba/security/CVE-2013-0454
2013-03-26
Published