VDB

MAGEIA-2013-348

MAGEIA-2013-348 PUBLISHED

Updated samba packages fix security vulnerabilities: Samba versions before 3.6.20 do not check the underlying file or directory ACL when opening an alternate data stream (CVE-2013-4475). Samba is not configured by default to support alternate data streams, so only servers that have enabled the streams_depot or streams_xattr VFS modules are affected.

Affected Products

VendorProductVersions
Mageiasamba0, 3.6.15-1.2.mga3
Mageiasamba0, 3.6.5-2.4.mga2

Timeline

  • Nov 22, 2013 CVE Updated
  • Nov 22, 2013 CVE Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›