Unrated severityNVD Advisory· Published Nov 13, 2013· Updated Apr 29, 2026
CVE-2013-4476
CVE-2013-4476
Description
Samba 4.0.x before 4.0.11 and 4.1.x before 4.1.1, when LDAP or HTTP is provided over SSL, uses world-readable permissions for a private key, which allows local users to obtain sensitive information by reading the key file, as demonstrated by access to the local filesystem on an AD domain controller.
Affected products
13cpe:2.3:a:samba:samba:4.0.0:*:*:*:*:*:*:*+ 11 more
- cpe:2.3:a:samba:samba:4.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.0.10:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.0.5:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.0.6:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.0.7:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.0.8:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.0.9:*:*:*:*:*:*:*
- cpe:2.3:a:samba:samba:4.1.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- www.samba.org/samba/security/CVE-2013-4476nvdVendor Advisory
- lists.opensuse.org/opensuse-updates/2013-11/msg00083.htmlnvd
- lists.opensuse.org/opensuse-updates/2013-12/msg00088.htmlnvd
- security.gentoo.org/glsa/glsa-201502-15.xmlnvd
- www.samba.org/samba/history/samba-4.0.11.htmlnvd
- www.samba.org/samba/history/samba-4.1.1.htmlnvd
News mentions
0No linked articles in our index yet.