Release date:
Updated on: 2013-02-03
Affected Systems:
Samba 4.x
Samba 3.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 57631
CVE (CAN) ID: CVE-2013-0213
Samba is a set of programs that implement the SMB (Server Messages Block) protocol, cross-platform file sharing and print sharing services.
Samba 3.0-4.0.1 allows users to perform certain HTTP request operations without verifying these requests. This allows attackers to hijack by clicking the button and entice the Administrator to change Samba settings.
<* Source: Jann Horn
Link: http://secunia.com/advisories/51994/
Http://www.samba.org/samba/security/CVE-2013-0213
*>
Suggestion:
--------------------------------------------------------------------------------
Temporary solution:
If you cannot install or upgrade the patch immediately, NSFOCUS recommends that you take the following measures to reduce the threat:
* Make sure that SWAT is disabled. Edit the smb. conf file to configure Samba.
Vendor patch:
Samba
-----
Samba has released a Security Bulletin (CVE-2013-0213) and patches for this:
CVE-2013-0213: CVE-2013-0213.html:
Link: http://www.samba.org/samba/security/CVE-2013-0213