Lucene search

K
ubuntucveUbuntu.comUB:CVE-2013-0454
HistoryMar 26, 2013 - 12:00 a.m.

CVE-2013-0454

2013-03-2600:00:00
ubuntu.com
ubuntu.com
9

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:S/C:N/I:P/A:N

EPSS

0.002

Percentile

52.3%

The SMB2 implementation in Samba 3.6.x before 3.6.6, as used on the IBM
Storwize V7000 Unified 1.3 before 1.3.2.3 and 1.4 before 1.4.0.1 and
possibly other products, does not properly enforce CIFS share attributes,
which allows remote authenticated users to (1) write to a read-only share;
(2) trigger data-integrity problems related to the oplock, locking,
coherency, or leases attribute; or (3) have an unspecified impact by
leveraging incorrect handling of the browseable or “hide unreadable”
parameter.

Bugs

OSVersionArchitecturePackageVersionFilename
ubuntu12.04noarchsamba< 2:3.6.3-2ubuntu2.6UNKNOWN

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:S/C:N/I:P/A:N

EPSS

0.002

Percentile

52.3%