CVE-2013-0454
Summary
| CVE | CVE-2013-0454 |
|---|---|
| State | PUBLISHED |
| Assigner | ibm |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-03-26 21:55:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The SMB2 implementation in Samba 3.6.x before 3.6.6, as used on the IBM Storwize V7000 Unified 1.3 before 1.3.2.3 and 1.4 before 1.4.0.1 and possibly other products, does not properly enforce CIFS share attributes, which allows remote authenticated users to (1) write to a read-only share; (2) trigger data-integrity problems related to the oplock, locking, coherency, or leases attribute; or (3) have an unspecified impact by leveraging incorrect handling of the browseable or "hide unreadable" parameter. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:L/Au:S/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Canonical | Ubuntu Linux | 12.04 | - | lts | All |
| Application | Ibm | Storwize | v7000 | 1.3 | All | All |
| Application | Ibm | Storwize | v7000 | 1.4 | All | All |
| Application | Samba | Samba | 3.6.0 | All | All | All |
| Application | Samba | Samba | 3.6.1 | All | All | All |
| Application | Samba | Samba | 3.6.2 | All | All | All |
| Application | Samba | Samba | 3.6.3 | All | All | All |
| Application | Samba | Samba | 3.6.4 | All | All | All |
| Application | Samba | Samba | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| USN-1802-1: Samba vulnerability | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | Vendor Advisory |
| Bug Access Denied | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.samba.org | |
| Security Bulletin: Storwize V7000 Unified Fix Available for CIFS Attribute Vulnerability (CVE-2013-0454) | af854a3a-2127-422b-91ae-364da2661108 | www.ibm.com | Vendor Advisory |
| [Announce] Samba 3.6.6 Available for Download | af854a3a-2127-422b-91ae-364da2661108 | lists.samba.org | |
| Samba - Security Announcement Archive | af854a3a-2127-422b-91ae-364da2661108 | www.samba.org | Vendor Advisory |
| 928419 – (CVE-2013-0454) CVE-2013-0454 samba: the SMB2 server does not release unused shares | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.