Release date:
Updated on: 2013-02-03
Affected Systems:
Samba 4.x
Samba 3.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 57631
CVE (CAN) ID: CVE-2013-0214
Samba is a set of programs that implement the SMB (Server Messages Block) protocol, cross-platform file sharing and print sharing services.
Samba Web Administration Tool (SWAT) in Samba 3.0-4.0.1 has a Cross-Site Request Forgery Vulnerability. To successfully exploit this vulnerability, attackers need to know the victim's password.
<* Source: Jann Horn
Link: http://secunia.com/advisories/51994/
Http://www.samba.org/samba/security/CVE-2013-0214
*>
Suggestion:
--------------------------------------------------------------------------------
Temporary solution:
If you cannot install or upgrade the patch immediately, NSFOCUS recommends that you take the following measures to reduce the threat:
* Make sure that SWAT is disabled. Edit the smb. conf file to configure Samba.
Vendor patch:
Samba
-----
Samba has released a Security Bulletin (CVE-2013-0214) and patches for this:
CVE-2013-0214: Cross-Site Request Forgery in SWAT
Link: http://www.samba.org/samba/security/CVE-2013-0214