← Back

CVE-2013-6442

nvd nist
Published: Mar 14, 2014Modified: May 6, 2026

JSON object

Loading...
5.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:N
Exploitability: 8.6 / Impact: 4.9
Source: NVD

Description

The owner_set function in smbcacls.c in smbcacls in Samba 4.0.x before 4.0.16 and 4.1.x before 4.1.6 removes an ACL during use of a --chown or --chgrp option, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging an unintended administrative change.

Affected (22)

Products: Samba: Samba
1 product
Samba
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Samba
Version 4.1.0
Version 4.1.1
Version 4.1.2
Version 4.1.3
Version 4.1.4
Version 4.1.5
Configuration B
16 vulnerable
Vulnerable SoftwareAffected Versions
Samba
Version 4.0.0
Version 4.0.10
Version 4.0.11
Version 4.0.12
Version 4.0.13
Version 4.0.14
Version 4.0.15
Version 4.0.1
Version 4.0.2
Version 4.0.3
Version 4.0.4
Version 4.0.5
Version 4.0.6
Version 4.0.7
Version 4.0.8
Version 4.0.9

Related CWEs

References (16)

Timeline

No history available yet.