CVE-2013-6442
published 2014-03-14CVE-2013-6442: The owner_set function in smbcacls.c in smbcacls in Samba 4.0.x before 4.0.16 and 4.1.x before 4.1.6 removes an ACL during use of a --chown or --chgrp option…
PriorityP339medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EPSS
4.10%
89.7th percentile
The owner_set function in smbcacls.c in smbcacls in Samba 4.0.x before 4.0.16 and 4.1.x before 4.1.6 removes an ACL during use of a --chown or --chgrp option, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging an unintended administrative change.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | samba | < samba 2:4.1.6+dfsg-1 (bookworm) | samba 2:4.1.6+dfsg-1 (bookworm) |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | >= 0 < 2:4.1.6+dfsg-1 | 2:4.1.6+dfsg-1 |
| samba | samba | >= 0 < 2:4.1.6+dfsg-1 | 2:4.1.6+dfsg-1 |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv5.8MEDIUM
vendor_debian5.8LOW
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Samba up to 4.1.5 smbcacls smbcacls.c owner_set --chown/--chgrp access control (Bug 10327 / Nessus ID 73046)
vuldb·2026-05-08·CVSS 5.8
CVE-2013-6442 [MEDIUM] Samba up to 4.1.5 smbcacls smbcacls.c owner_set --chown/--chgrp access control (Bug 10327 / Nessus ID 73046)
A vulnerability, which was classified as critical, was found in Samba. Impacted is the function owner_set of the file smbcacls.c of the component smbcacls. Such manipulation of the argument --chown/--chgrp leads to improper access controls.
This vulnerability is traded as CVE-2013-6442. The attack may be launched remotely. There is no exploit available.
You should upgrade the affected component.
GHSA
GHSA-qgqp-hrvv-cxc3: The owner_set function in smbcacls
ghsa_unreviewed·2022-05-17
CVE-2013-6442 [MEDIUM] GHSA-qgqp-hrvv-cxc3: The owner_set function in smbcacls
The owner_set function in smbcacls.c in smbcacls in Samba 4.0.x before 4.0.16 and 4.1.x before 4.1.6 removes an ACL during use of a --chown or --chgrp option, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging an unintended administrative change.
OSV
CVE-2013-6442: The owner_set function in smbcacls
osv·2014-03-14·CVSS 5.8
CVE-2013-6442 [MEDIUM] CVE-2013-6442: The owner_set function in smbcacls
The owner_set function in smbcacls.c in smbcacls in Samba 4.0.x before 4.0.16 and 4.1.x before 4.1.6 removes an ACL during use of a --chown or --chgrp option, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging an unintended administrative change.
Red Hat
samba: smbcacls will delete ACL lists in certain circumstances
vendor_redhat·2014-03-12·CVSS 5.8
CVE-2013-6442 [MEDIUM] samba: smbcacls will delete ACL lists in certain circumstances
samba: smbcacls will delete ACL lists in certain circumstances
The owner_set function in smbcacls.c in smbcacls in Samba 4.0.x before 4.0.16 and 4.1.x before 4.1.6 removes an ACL during use of a --chown or --chgrp option, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging an unintended administrative change.
Package: samba (Red Hat Enterprise Linux 5) - Not affected
Package: samba3x (Red Hat Enterprise Linux 5) - Not affected
Package: samba (Red Hat Enterprise Linux 6) - Not affected
Package: samba (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2013-6442: samba - The owner_set function in smbcacls.c in smbcacls in Samba 4.0.x before 4.0.16 an...
vendor_debian·2013·CVSS 5.8
CVE-2013-6442 [MEDIUM] CVE-2013-6442: samba - The owner_set function in smbcacls.c in smbcacls in Samba 4.0.x before 4.0.16 an...
The owner_set function in smbcacls.c in smbcacls in Samba 4.0.x before 4.0.16 and 4.1.x before 4.1.6 removes an ACL during use of a --chown or --chgrp option, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging an unintended administrative change.
Scope: local
bookworm: resolved (fixed in 2:4.1.6+dfsg-1)
bullseye: resolved (fixed in 2:4.1.6+dfsg-1)
forky: resolved (fixed in 2:4.1.6+dfsg-1)
sid: resolved (fixed in 2:4.1.6+dfsg-1)
trixie: resolved (fixed in 2:4.1.6+dfsg-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4496 CVE-2013-6442 samba: various flaws [fedora-all]
bugzilla·2014-03-12·CVSS 5.0
CVE-2013-4496 [MEDIUM] CVE-2013-4496 CVE-2013-6442 samba: various flaws [fedora-all]
CVE-2013-4496 CVE-2013-6442 samba: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects multiple su
Bugzilla
CVE-2013-6442 samba: smbcacls will delete ACL lists in certain circumstances
bugzilla·2013-12-17·CVSS 5.8
CVE-2013-6442 [MEDIUM] CVE-2013-6442 samba: smbcacls will delete ACL lists in certain circumstances
CVE-2013-6442 samba: smbcacls will delete ACL lists in certain circumstances
Samba upstream reports that:
Samba versions 4.0.0 and above have a flaw in the smbcacls command. If
smbcacls is used with the "-C|--chown name" or "-G|--chgrp name"
command options it will remove the existing ACL on the object being
modified, leaving the file or directory unprotected.
This issue can be worked around by using chown or similar tools to modify owners on files and directories.
Upstream bug: https://bugzilla.samba.org/show_bug.cgi?id=10327
Discussion:
Public via:
http://www.samba.org/samba/security/CVE-2013-6442
---
Created samba tracking bugs for this issue:
Affects: fedora-all [bug 1075429]
---
samba-4.1.6-1.fc20 has been pushed to the Fedora 20 stable repository. If problems still persis
http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136864.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-June/134717.htmlhttp://lists.opensuse.org/opensuse-updates/2014-03/msg00062.htmlhttp://www.samba.org/samba/history/samba-4.0.16.htmlhttp://www.samba.org/samba/history/samba-4.1.6.htmlhttp://www.samba.org/samba/security/CVE-2013-6442http://www.securityfocus.com/bid/66232https://bugzilla.samba.org/show_bug.cgi?id=10327http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136864.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-June/134717.htmlhttp://lists.opensuse.org/opensuse-updates/2014-03/msg00062.htmlhttp://www.samba.org/samba/history/samba-4.0.16.htmlhttp://www.samba.org/samba/history/samba-4.1.6.htmlhttp://www.samba.org/samba/security/CVE-2013-6442http://www.securityfocus.com/bid/66232https://bugzilla.samba.org/show_bug.cgi?id=10327
2014-03-14
Published