Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2013-4476

Опубликовано: 13 нояб. 2013
Источник: debian
EPSS Низкий

Описание

Samba 4.0.x before 4.0.11 and 4.1.x before 4.1.1, when LDAP or HTTP is provided over SSL, uses world-readable permissions for a private key, which allows local users to obtain sensitive information by reading the key file, as demonstrated by access to the local filesystem on an AD domain controller.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
sambafixed2:4.0.11+dfsg-1package
sambanot-affectedwheezypackage
sambanot-affectedsqueezepackage
samba4removedpackage
samba4fixed4.0.0~beta2+dfsg1-3.2+deb7u1wheezypackage

EPSS

Процентиль: 35%
0.00435
Низкий

Связанные уязвимости

ubuntu
больше 12 лет назад

Samba 4.0.x before 4.0.11 and 4.1.x before 4.1.1, when LDAP or HTTP is provided over SSL, uses world-readable permissions for a private key, which allows local users to obtain sensitive information by reading the key file, as demonstrated by access to the local filesystem on an AD domain controller.

redhat
почти 13 лет назад

Samba 4.0.x before 4.0.11 and 4.1.x before 4.1.1, when LDAP or HTTP is provided over SSL, uses world-readable permissions for a private key, which allows local users to obtain sensitive information by reading the key file, as demonstrated by access to the local filesystem on an AD domain controller.

nvd
больше 12 лет назад

Samba 4.0.x before 4.0.11 and 4.1.x before 4.1.1, when LDAP or HTTP is provided over SSL, uses world-readable permissions for a private key, which allows local users to obtain sensitive information by reading the key file, as demonstrated by access to the local filesystem on an AD domain controller.

github
около 4 лет назад

Samba 4.0.x before 4.0.11 and 4.1.x before 4.1.1, when LDAP or HTTP is provided over SSL, uses world-readable permissions for a private key, which allows local users to obtain sensitive information by reading the key file, as demonstrated by access to the local filesystem on an AD domain controller.

CVSS3: 3.2
fstec
больше 12 лет назад

Уязвимость пакета программ сетевого взаимодействия Samba, связанная с недостатками в механизме криптографической защиты, позволяющая нарушителю получить доступ к конфиденциальным данным

EPSS

Процентиль: 35%
0.00435
Низкий