[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248364

 
 

909

 
 

195388

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2617-1 samba -- several issues

ID: oval:org.secpod.oval:def:600957Date: (C)2013-02-06   (M)2023-12-07
Class: PATCHFamily: unix




Jann Horn had reported two vulnerabilities in Samba, a popular cross-platform network file and printer sharing suite. In particular, these vulnerabilities affect to SWAT, the Samba Web Administration Tool. CVE-2013-0213: Clickjacking issue in SWAT An attacker can integrate a SWAT page into a malicious web page via a frame or iframe and then overlaid by other content. If an authenticated valid user interacts with this malicious web page, she might perform unintended changes in the Samba settings. CVE-2013-0214: Potential Cross-site request forgery An attacker can persuade a valid SWAT user, who is logged in, to click in a malicious link and trigger arbitrary unintended changes in the Samba settings.

Platform:
Debian 6.0
Product:
samba
Reference:
DSA-2617-1
CVE-2013-0213
CVE-2013-0214
CVE    2
CVE-2013-0213
CVE-2013-0214
CPE    166
cpe:/a:samba:samba:3.0.2a
cpe:/a:samba:samba:3.1
cpe:/o:debian:debian_linux:6.x
cpe:/a:samba:samba:3.0.21a
...

© SecPod Technologies