CVE-2013-4476
Published Nov 13, 2013
Last updated 10 years ago
Overview
- Description
- Samba 4.0.x before 4.0.11 and 4.1.x before 4.1.1, when LDAP or HTTP is provided over SSL, uses world-readable permissions for a private key, which allows local users to obtain sensitive information by reading the key file, as demonstrated by access to the local filesystem on an AD domain controller.
- Source
- secalert@redhat.com
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 1.2
- Impact score
- 2.9
- Exploitability score
- 1.9
- Vector string
- AV:L/AC:H/Au:N/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-310
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:samba:samba:4.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0DEEFFF7-DF7C-4641-81A9-1CD64DC29DEC" }, { "criteria": "cpe:2.3:a:samba:samba:4.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2855B3F6-49B6-4D25-BEAC-4D1797D1E100" }, { "criteria": "cpe:2.3:a:samba:samba:4.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6C1F1993-70A2-4104-85AF-3BECB330AB24" }, { "criteria": "cpe:2.3:a:samba:samba:4.0.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E955458C-8F5C-4D55-9F78-9E1CB4416F10" }, { "criteria": "cpe:2.3:a:samba:samba:4.0.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "866FF7AC-19EA-49E7-B423-9FF57839B580" }, { "criteria": "cpe:2.3:a:samba:samba:4.0.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2A1A64C7-B039-4724-B06C-EAC898EB3B73" }, { "criteria": "cpe:2.3:a:samba:samba:4.0.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C572E25A-4B44-426D-B637-292A08766D7F" }, { "criteria": "cpe:2.3:a:samba:samba:4.0.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6D96D806-ED52-4010-9F5F-F84E33C245D2" }, { "criteria": "cpe:2.3:a:samba:samba:4.0.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "643FC7D2-FC39-43FA-99E6-805553FE1DCB" }, { "criteria": "cpe:2.3:a:samba:samba:4.0.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E2B95519-0C9D-473C-912D-E350106DC4CD" }, { "criteria": "cpe:2.3:a:samba:samba:4.0.10:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DC603E1A-7882-45F0-9E8D-157F191C0FD3" }, { "criteria": "cpe:2.3:a:samba:samba:4.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6CB9C10B-284E-48CD-A524-1A6BF828AED9" } ], "operator": "OR" } ] } ]