FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2013-6442

This CVE name corresponds to:

Entered Topic
2014-03-11 samba -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2013-6442
Phase Assigned(20131104)

Description

The owner_set function in smbcacls.c in smbcacls in Samba 4.0.x before 4.0.16 and 4.1.x before 4.1.6 removes an ACL during use of a --chown or --chgrp option, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging an unintended administrative change.

References

Source Reference
CONFIRM http://www.samba.org/samba/history/samba-4.0.16.html
CONFIRM http://www.samba.org/samba/history/samba-4.1.6.html
CONFIRM http://www.samba.org/samba/security/CVE-2013-6442
CONFIRM https://bugzilla.samba.org/show_bug.cgi?id=10327
SUSE openSUSE-SU-2014:0404
BID 66232