5.8
CVSSv2

CVE-2013-6442

Published: 14/03/2014 Updated: 07/01/2017
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

The owner_set function in smbcacls.c in smbcacls in Samba 4.0.x prior to 4.0.16 and 4.1.x prior to 4.1.6 removes an ACL during use of a --chown or --chgrp option, which allows remote malicious users to bypass intended access restrictions in opportunistic circumstances by leveraging an unintended administrative change.

Vulnerable Product Search on Vulmon Subscribe to Product

samba samba 4.1.1

samba samba 4.1.2

samba samba 4.1.4

samba samba 4.1.5

samba samba 4.1.0

samba samba 4.1.3

samba samba 4.0.0

samba samba 4.0.1

samba samba 4.0.4

samba samba 4.0.5

samba samba 4.0.14

samba samba 4.0.15

samba samba 4.0.2

samba samba 4.0.3

samba samba 4.0.12

samba samba 4.0.13

samba samba 4.0.8

samba samba 4.0.9

samba samba 4.0.10

samba samba 4.0.11

samba samba 4.0.6

samba samba 4.0.7