CVE-2013-4475: Medium severity samba vulnerability
Samba 3.2.x through 3.6.x before 3.6.20, 4.0.x before 4.0.11, and 4.1.x before 4.1.1, when vfsstreamsdepot or vfsstreamsxattr is enabled, allows remote attackers to bypass intended file restrictions by leveraging ACL differences between a file and an associated alternate data stream (ADS).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4475?
CVE-2013-4475 has a medium severity level, as it allows unauthorized access through specific configuration settings.
How do I fix CVE-2013-4475?
To fix CVE-2013-4475, update Samba to the latest version, specifically to 3.6.20 or higher, 4.0.11 or higher, or 4.1.1 or higher.
Which Samba versions are affected by CVE-2013-4475?
CVE-2013-4475 affects Samba versions from 3.2.x to 3.6.x before 3.6.20, 4.0.x before 4.0.11, and 4.1.x before 4.1.1.
Can CVE-2013-4475 be exploited remotely?
Yes, CVE-2013-4475 can be exploited remotely by attackers leveraging alternate data streams.
What configurations are involved in CVE-2013-4475?
The vulnerability involves configurations where vfs_streams_depot or vfs_streams_xattr is enabled.