VYPR

rpm package

opensuse/samba&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/samba&distro=openSUSE%20Tumbleweed

Vulnerabilities (166)

  • CVE-2013-4496Mar 14, 2014
    affected < 4.5.0-1.1fixed 4.5.0-1.1

    Samba 3.x before 3.6.23, 4.0.x before 4.0.16, and 4.1.x before 4.1.6 does not enforce the password-guessing protection mechanism for all interfaces, which makes it easier for remote attackers to obtain access via brute-force ChangePasswordUser2 (1) SAMR or (2) RAP attempts.

  • CVE-2013-4408Dec 10, 2013
    affected < 4.5.0-1.1fixed 4.5.0-1.1

    Heap-based buffer overflow in the dcerpc_read_ncacn_packet_done function in librpc/rpc/dcerpc_util.c in winbindd in Samba 3.x before 3.6.22, 4.0.x before 4.0.13, and 4.1.x before 4.1.3 allows remote AD domain controllers to execute arbitrary code via an invalid fragment length in

  • CVE-2012-6150Dec 3, 2013
    affected < 4.5.0-1.1fixed 4.5.0-1.1

    The winbind_name_list_to_sid_string_list function in nsswitch/pam_winbind.c in Samba through 4.1.2 handles invalid require_membership_of group names by accepting authentication by any user, which allows remote authenticated users to bypass intended access restrictions in opportun

  • CVE-2013-4476Nov 13, 2013
    affected < 4.5.0-1.1fixed 4.5.0-1.1

    Samba 4.0.x before 4.0.11 and 4.1.x before 4.1.1, when LDAP or HTTP is provided over SSL, uses world-readable permissions for a private key, which allows local users to obtain sensitive information by reading the key file, as demonstrated by access to the local filesystem on an A

  • CVE-2013-4475Nov 13, 2013
    affected < 4.5.0-1.1fixed 4.5.0-1.1

    Samba 3.2.x through 3.6.x before 3.6.20, 4.0.x before 4.0.11, and 4.1.x before 4.1.1, when vfs_streams_depot or vfs_streams_xattr is enabled, allows remote attackers to bypass intended file restrictions by leveraging ACL differences between a file and an associated alternate data

  • CVE-2013-4124Aug 6, 2013
    affected < 4.5.0-1.1fixed 4.5.0-1.1

    Integer overflow in the read_nttrans_ea_list function in nttrans.c in smbd in Samba 3.x before 3.5.22, 3.6.x before 3.6.17, and 4.x before 4.0.8 allows remote attackers to cause a denial of service (memory consumption) via a malformed packet.

  • CVE-2013-0454Mar 26, 2013
    affected < 4.5.0-1.1fixed 4.5.0-1.1

    The SMB2 implementation in Samba 3.6.x before 3.6.6, as used on the IBM Storwize V7000 Unified 1.3 before 1.3.2.3 and 1.4 before 1.4.0.1 and possibly other products, does not properly enforce CIFS share attributes, which allows remote authenticated users to (1) write to a read-on

  • CVE-2013-1863Mar 19, 2013
    affected < 4.5.0-1.1fixed 4.5.0-1.1

    Samba 4.x before 4.0.4, when configured as an Active Directory domain controller, uses world-writable permissions on non-default CIFS shares, which allows remote authenticated users to read, modify, create, or delete arbitrary files via standard filesystem operations.

  • CVE-2013-0214Feb 2, 2013
    affected < 4.5.0-1.1fixed 4.5.0-1.1

    Cross-site request forgery (CSRF) vulnerability in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.21, 3.6.x before 3.6.12, and 4.x before 4.0.2 allows remote attackers to hijack the authentication of arbitrary users by leveraging knowledge of a password and comp

  • CVE-2013-0213Feb 2, 2013
    affected < 4.5.0-1.1fixed 4.5.0-1.1

    The Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.21, 3.6.x before 3.6.12, and 4.x before 4.0.2 allows remote attackers to conduct clickjacking attacks via a (1) FRAME or (2) IFRAME element.

  • CVE-2013-0172Jan 17, 2013
    affected < 4.5.0-1.1fixed 4.5.0-1.1

    Samba 4.0.x before 4.0.1, in certain Active Directory domain-controller configurations, does not properly interpret Access Control Entries that are based on an objectClass, which allows remote authenticated users to bypass intended restrictions on modifying LDAP directory objects

  • CVE-2012-2111Apr 30, 2012
    affected < 4.5.0-1.1fixed 4.5.0-1.1

    The (1) CreateAccount, (2) OpenAccount, (3) AddAccountRights, and (4) RemoveAccountRights LSA RPC procedures in smbd in Samba 3.4.x before 3.4.17, 3.5.x before 3.5.15, and 3.6.x before 3.6.5 do not properly restrict modifications to the privileges database, which allows remote au

  • CVE-2012-1182Apr 10, 2012
    affected < 4.5.0-1.1fixed 4.5.0-1.1

    The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 does not implement validation of an array length in a manner consistent with validation of array memory allocation, which allows remote attackers to execute arbitrary code via a crafted

  • CVE-2012-0870Feb 23, 2012
    affected < 4.5.0-1.1fixed 4.5.0-1.1

    Heap-based buffer overflow in process.c in smbd in Samba 3.0, as used in the file-sharing service on the BlackBerry PlayBook tablet before 2.0.0.7971 and other products, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a B

  • CVE-2012-0817Jan 30, 2012
    affected < 4.5.0-1.1fixed 4.5.0-1.1

    Memory leak in smbd in Samba 3.6.x before 3.6.3 allows remote attackers to cause a denial of service (memory and CPU consumption) by making many connection requests.

  • CVE-2011-2694Jul 29, 2011
    affected < 4.5.0-1.1fixed 4.5.0-1.1

    Cross-site scripting (XSS) vulnerability in the chg_passwd function in web/swat.c in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allows remote authenticated administrators to inject arbitrary web script or HTML via the username parameter to the passwd prog

  • CVE-2011-2522Jul 29, 2011
    affected < 4.5.0-1.1fixed 4.5.0-1.1

    Multiple cross-site request forgery (CSRF) vulnerabilities in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allow remote attackers to hijack the authentication of administrators for requests that (1) shut down daemons, (2) start daemons, (3) add shares, (4)

  • CVE-2011-0719Mar 1, 2011
    affected < 4.5.0-1.1fixed 4.5.0-1.1

    Samba 3.x before 3.3.15, 3.4.x before 3.4.12, and 3.5.x before 3.5.7 does not perform range checks for file descriptors before use of the FD_SET macro, which allows remote attackers to cause a denial of service (stack memory corruption, and infinite loop or daemon crash) by openi

  • CVE-2010-3069Sep 15, 2010
    affected < 4.5.0-1.1fixed 4.5.0-1.1

    Stack-based buffer overflow in the (1) sid_parse and (2) dom_sid_parse functions in Samba before 3.5.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted Windows Security ID (SID) on a file share.

  • CVE-2010-2063Jun 17, 2010
    affected < 4.5.0-1.1fixed 4.5.0-1.1

    Buffer overflow in the SMB1 packet chaining implementation in the chain_reply function in process.c in smbd in Samba 3.0.x before 3.3.13 allows remote attackers to cause a denial of service (memory corruption and daemon crash) or possibly execute arbitrary code via a crafted fiel

Page 7 of 9