CVE-2013-0213: Input Validation
The Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.21, 3.6.x before 3.6.12, and 4.x before 4.0.2 allows remote attackers to conduct clickjacking attacks via a (1) FRAME or (2) IFRAME element.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0213?
CVE-2013-0213 is considered a medium severity vulnerability because it allows remote attackers to conduct clickjacking attacks.
How do I fix CVE-2013-0213?
To fix CVE-2013-0213, you should upgrade to Samba versions 3.5.21, 3.6.12, or 4.0.2 or later.
What systems are affected by CVE-2013-0213?
CVE-2013-0213 affects Samba versions 3.0.0 through 4.0.1, including various 3.x and 4.x series releases.
What type of attack does CVE-2013-0213 enable?
CVE-2013-0213 enables clickjacking attacks, which can trick users into interacting with hidden webpage elements.
Is there a workaround for CVE-2013-0213?
While the best solution is to update Samba, a temporary workaround may involve disabling SWAT or restricting access to it.