rpm package
opensuse/samba&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/samba&distro=openSUSE%20Tumbleweed
Vulnerabilities (179)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2013-0213 | — | < 4.5.0-1.1 | 4.5.0-1.1 | Feb 2, 2013 | The Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.21, 3.6.x before 3.6.12, and 4.x before 4.0.2 allows remote attackers to conduct clickjacking attacks via a (1) FRAME or (2) IFRAME element. | ||
| CVE-2013-0172 | — | < 4.5.0-1.1 | 4.5.0-1.1 | Jan 17, 2013 | Samba 4.0.x before 4.0.1, in certain Active Directory domain-controller configurations, does not properly interpret Access Control Entries that are based on an objectClass, which allows remote authenticated users to bypass intended restrictions on modifying LDAP directory objects | ||
| CVE-2012-2111 | — | < 4.5.0-1.1 | 4.5.0-1.1 | Apr 30, 2012 | The (1) CreateAccount, (2) OpenAccount, (3) AddAccountRights, and (4) RemoveAccountRights LSA RPC procedures in smbd in Samba 3.4.x before 3.4.17, 3.5.x before 3.5.15, and 3.6.x before 3.6.5 do not properly restrict modifications to the privileges database, which allows remote au | ||
| CVE-2012-1182 | — | < 4.5.0-1.1 | 4.5.0-1.1 | Apr 10, 2012 | The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 does not implement validation of an array length in a manner consistent with validation of array memory allocation, which allows remote attackers to execute arbitrary code via a crafted | ||
| CVE-2012-0870 | — | < 4.5.0-1.1 | 4.5.0-1.1 | Feb 23, 2012 | Heap-based buffer overflow in process.c in smbd in Samba 3.0, as used in the file-sharing service on the BlackBerry PlayBook tablet before 2.0.0.7971 and other products, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a B | ||
| CVE-2012-0817 | — | < 4.5.0-1.1 | 4.5.0-1.1 | Jan 30, 2012 | Memory leak in smbd in Samba 3.6.x before 3.6.3 allows remote attackers to cause a denial of service (memory and CPU consumption) by making many connection requests. | ||
| CVE-2011-2694 | — | < 4.5.0-1.1 | 4.5.0-1.1 | Jul 29, 2011 | Cross-site scripting (XSS) vulnerability in the chg_passwd function in web/swat.c in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allows remote authenticated administrators to inject arbitrary web script or HTML via the username parameter to the passwd prog | ||
| CVE-2011-2522 | — | < 4.5.0-1.1 | 4.5.0-1.1 | Jul 29, 2011 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allow remote attackers to hijack the authentication of administrators for requests that (1) shut down daemons, (2) start daemons, (3) add shares, (4) | ||
| CVE-2011-0719 | — | < 4.5.0-1.1 | 4.5.0-1.1 | Mar 1, 2011 | Samba 3.x before 3.3.15, 3.4.x before 3.4.12, and 3.5.x before 3.5.7 does not perform range checks for file descriptors before use of the FD_SET macro, which allows remote attackers to cause a denial of service (stack memory corruption, and infinite loop or daemon crash) by openi | ||
| CVE-2010-3069 | — | < 4.5.0-1.1 | 4.5.0-1.1 | Sep 15, 2010 | Stack-based buffer overflow in the (1) sid_parse and (2) dom_sid_parse functions in Samba before 3.5.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted Windows Security ID (SID) on a file share. | ||
| CVE-2010-2063 | — | < 4.5.0-1.1 | 4.5.0-1.1 | Jun 17, 2010 | Buffer overflow in the SMB1 packet chaining implementation in the chain_reply function in process.c in smbd in Samba 3.0.x before 3.3.13 allows remote attackers to cause a denial of service (memory corruption and daemon crash) or possibly execute arbitrary code via a crafted fiel | ||
| CVE-2010-1642 | — | < 4.5.0-1.1 | 4.5.0-1.1 | Jun 17, 2010 | The reply_sesssetup_and_X_spnego function in sesssetup.c in smbd in Samba before 3.4.8 and 3.5.x before 3.5.2 allows remote attackers to trigger an out-of-bounds read, and cause a denial of service (process crash), via a \xff\xff security blob length in a Session Setup AndX reque | ||
| CVE-2010-1635 | — | < 4.5.0-1.1 | 4.5.0-1.1 | Jun 17, 2010 | The chain_reply function in process.c in smbd in Samba before 3.4.8 and 3.5.x before 3.5.2 allows remote attackers to cause a denial of service (NULL pointer dereference and process crash) via a Negotiate Protocol request with a certain 0x0003 field value followed by a Session Se | ||
| CVE-2010-0926 | — | < 4.5.0-1.1 | 4.5.0-1.1 | Mar 10, 2010 | The default configuration of smbd in Samba before 3.3.11, 3.4.x before 3.4.6, and 3.5.x before 3.5.0rc3, when a writable share exists, allows remote authenticated users to leverage a directory traversal vulnerability, and access arbitrary files, by using the symlink command in sm | ||
| CVE-2010-0728 | — | < 4.5.0-1.1 | 4.5.0-1.1 | Mar 10, 2010 | smbd in Samba 3.3.11, 3.4.6, and 3.5.0, when libcap support is enabled, runs with the CAP_DAC_OVERRIDE capability, which allows remote authenticated users to bypass intended file permissions via standard filesystem operations with any client. | ||
| CVE-2010-0787 | — | < 4.5.0-1.1 | 4.5.0-1.1 | Mar 2, 2010 | client/mount.cifs.c in mount.cifs in smbfs in Samba 3.0.22, 3.0.28a, 3.2.3, 3.3.2, 3.4.0, and 3.4.5 allows local users to mount a CIFS share on an arbitrary mountpoint, and gain privileges, via a symlink attack on the mountpoint directory file. | ||
| CVE-2010-0547 | — | < 4.5.0-1.1 | 4.5.0-1.1 | Feb 4, 2010 | client/mount.cifs.c in mount.cifs in smbfs in Samba 3.4.5 and earlier does not verify that the (1) device name and (2) mountpoint strings are composed of valid characters, which allows local users to cause a denial of service (mtab corruption) via a crafted string. | ||
| CVE-2009-2948 | — | < 4.5.0-1.1 | 4.5.0-1.1 | Oct 7, 2009 | mount.cifs in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8 and 3.4 before 3.4.2, when mount.cifs is installed suid root, does not properly enforce permissions, which allows local users to read part of the credentials file and obtain the password by specifying the | ||
| CVE-2009-2906 | — | < 4.5.0-1.1 | 4.5.0-1.1 | Oct 7, 2009 | smbd in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8, and 3.4 before 3.4.2 allows remote authenticated users to cause a denial of service (infinite loop) via an unanticipated oplock break notification reply packet. | ||
| CVE-2009-2813 | — | < 4.5.0-1.1 | 4.5.0-1.1 | Sep 14, 2009 | Samba 3.4 before 3.4.2, 3.3 before 3.3.8, 3.2 before 3.2.15, and 3.0.12 through 3.0.36, as used in the SMB subsystem in Apple Mac OS X 10.5.8 when Windows File Sharing is enabled, Fedora 11, and other operating systems, does not properly handle errors in resolving pathnames, whic |
- CVE-2013-0213Feb 2, 2013affected < 4.5.0-1.1fixed 4.5.0-1.1
The Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.21, 3.6.x before 3.6.12, and 4.x before 4.0.2 allows remote attackers to conduct clickjacking attacks via a (1) FRAME or (2) IFRAME element.
- CVE-2013-0172Jan 17, 2013affected < 4.5.0-1.1fixed 4.5.0-1.1
Samba 4.0.x before 4.0.1, in certain Active Directory domain-controller configurations, does not properly interpret Access Control Entries that are based on an objectClass, which allows remote authenticated users to bypass intended restrictions on modifying LDAP directory objects
- CVE-2012-2111Apr 30, 2012affected < 4.5.0-1.1fixed 4.5.0-1.1
The (1) CreateAccount, (2) OpenAccount, (3) AddAccountRights, and (4) RemoveAccountRights LSA RPC procedures in smbd in Samba 3.4.x before 3.4.17, 3.5.x before 3.5.15, and 3.6.x before 3.6.5 do not properly restrict modifications to the privileges database, which allows remote au
- CVE-2012-1182Apr 10, 2012affected < 4.5.0-1.1fixed 4.5.0-1.1
The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 does not implement validation of an array length in a manner consistent with validation of array memory allocation, which allows remote attackers to execute arbitrary code via a crafted
- CVE-2012-0870Feb 23, 2012affected < 4.5.0-1.1fixed 4.5.0-1.1
Heap-based buffer overflow in process.c in smbd in Samba 3.0, as used in the file-sharing service on the BlackBerry PlayBook tablet before 2.0.0.7971 and other products, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a B
- CVE-2012-0817Jan 30, 2012affected < 4.5.0-1.1fixed 4.5.0-1.1
Memory leak in smbd in Samba 3.6.x before 3.6.3 allows remote attackers to cause a denial of service (memory and CPU consumption) by making many connection requests.
- CVE-2011-2694Jul 29, 2011affected < 4.5.0-1.1fixed 4.5.0-1.1
Cross-site scripting (XSS) vulnerability in the chg_passwd function in web/swat.c in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allows remote authenticated administrators to inject arbitrary web script or HTML via the username parameter to the passwd prog
- CVE-2011-2522Jul 29, 2011affected < 4.5.0-1.1fixed 4.5.0-1.1
Multiple cross-site request forgery (CSRF) vulnerabilities in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allow remote attackers to hijack the authentication of administrators for requests that (1) shut down daemons, (2) start daemons, (3) add shares, (4)
- CVE-2011-0719Mar 1, 2011affected < 4.5.0-1.1fixed 4.5.0-1.1
Samba 3.x before 3.3.15, 3.4.x before 3.4.12, and 3.5.x before 3.5.7 does not perform range checks for file descriptors before use of the FD_SET macro, which allows remote attackers to cause a denial of service (stack memory corruption, and infinite loop or daemon crash) by openi
- CVE-2010-3069Sep 15, 2010affected < 4.5.0-1.1fixed 4.5.0-1.1
Stack-based buffer overflow in the (1) sid_parse and (2) dom_sid_parse functions in Samba before 3.5.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted Windows Security ID (SID) on a file share.
- CVE-2010-2063Jun 17, 2010affected < 4.5.0-1.1fixed 4.5.0-1.1
Buffer overflow in the SMB1 packet chaining implementation in the chain_reply function in process.c in smbd in Samba 3.0.x before 3.3.13 allows remote attackers to cause a denial of service (memory corruption and daemon crash) or possibly execute arbitrary code via a crafted fiel
- CVE-2010-1642Jun 17, 2010affected < 4.5.0-1.1fixed 4.5.0-1.1
The reply_sesssetup_and_X_spnego function in sesssetup.c in smbd in Samba before 3.4.8 and 3.5.x before 3.5.2 allows remote attackers to trigger an out-of-bounds read, and cause a denial of service (process crash), via a \xff\xff security blob length in a Session Setup AndX reque
- CVE-2010-1635Jun 17, 2010affected < 4.5.0-1.1fixed 4.5.0-1.1
The chain_reply function in process.c in smbd in Samba before 3.4.8 and 3.5.x before 3.5.2 allows remote attackers to cause a denial of service (NULL pointer dereference and process crash) via a Negotiate Protocol request with a certain 0x0003 field value followed by a Session Se
- CVE-2010-0926Mar 10, 2010affected < 4.5.0-1.1fixed 4.5.0-1.1
The default configuration of smbd in Samba before 3.3.11, 3.4.x before 3.4.6, and 3.5.x before 3.5.0rc3, when a writable share exists, allows remote authenticated users to leverage a directory traversal vulnerability, and access arbitrary files, by using the symlink command in sm
- CVE-2010-0728Mar 10, 2010affected < 4.5.0-1.1fixed 4.5.0-1.1
smbd in Samba 3.3.11, 3.4.6, and 3.5.0, when libcap support is enabled, runs with the CAP_DAC_OVERRIDE capability, which allows remote authenticated users to bypass intended file permissions via standard filesystem operations with any client.
- CVE-2010-0787Mar 2, 2010affected < 4.5.0-1.1fixed 4.5.0-1.1
client/mount.cifs.c in mount.cifs in smbfs in Samba 3.0.22, 3.0.28a, 3.2.3, 3.3.2, 3.4.0, and 3.4.5 allows local users to mount a CIFS share on an arbitrary mountpoint, and gain privileges, via a symlink attack on the mountpoint directory file.
- CVE-2010-0547Feb 4, 2010affected < 4.5.0-1.1fixed 4.5.0-1.1
client/mount.cifs.c in mount.cifs in smbfs in Samba 3.4.5 and earlier does not verify that the (1) device name and (2) mountpoint strings are composed of valid characters, which allows local users to cause a denial of service (mtab corruption) via a crafted string.
- CVE-2009-2948Oct 7, 2009affected < 4.5.0-1.1fixed 4.5.0-1.1
mount.cifs in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8 and 3.4 before 3.4.2, when mount.cifs is installed suid root, does not properly enforce permissions, which allows local users to read part of the credentials file and obtain the password by specifying the
- CVE-2009-2906Oct 7, 2009affected < 4.5.0-1.1fixed 4.5.0-1.1
smbd in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8, and 3.4 before 3.4.2 allows remote authenticated users to cause a denial of service (infinite loop) via an unanticipated oplock break notification reply packet.
- CVE-2009-2813Sep 14, 2009affected < 4.5.0-1.1fixed 4.5.0-1.1
Samba 3.4 before 3.4.2, 3.3 before 3.3.8, 3.2 before 3.2.15, and 3.0.12 through 3.0.36, as used in the SMB subsystem in Apple Mac OS X 10.5.8 when Windows File Sharing is enabled, Fedora 11, and other operating systems, does not properly handle errors in resolving pathnames, whic
Page 8 of 9