cbcvebase.
CVE-2013-4475
published 2013-11-13

CVE-2013-4475: Samba 3.2.x through 3.6.x before 3.6.20, 4.0.x before 4.0.11, and 4.1.x before 4.1.1, when vfs_streams_depot or vfs_streams_xattr is enabled, allows remote…

PriorityP431medium4CVSS 2.0
AVNACHAuNCPIPAN
EPSS
9.02%
94.7th percentile
Samba 3.2.x through 3.6.x before 3.6.20, 4.0.x before 4.0.11, and 4.1.x before 4.1.1, when vfs_streams_depot or vfs_streams_xattr is enabled, allows remote attackers to bypass intended file restrictions by leveraging ACL differences between a file and an associated alternate data stream (ADS).

Affected

15 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debiansamba< samba 2:4.0.11+dfsg-1 (bookworm)samba 2:4.0.11+dfsg-1 (bookworm)
sambasamba
sambasamba>= 0 < 2:4.0.11+dfsg-12:4.0.11+dfsg-1
sambasamba>= 0 < 2:4.0.11+dfsg-12:4.0.11+dfsg-1
sambasamba>= 0 < 2:4.0.11+dfsg-12:4.0.11+dfsg-1
sambasamba>= 0 < 2:4.0.11+dfsg-12:4.0.11+dfsg-1
sambasamba>= 3.2.0 < 3.6.203.6.20
sambasamba>= 4.0.0 < 4.0.114.0.11

CVSS provenance

nvdv2.04.0MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:N
osv4.0MEDIUM
vendor_debian4.0LOW
vendor_redhat4.0MEDIUM
vendor_ubuntu3.6LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.