CVE-2013-4476
Publication date 13 November 2013
Last updated 24 July 2024
Ubuntu priority
Samba 4.0.x before 4.0.11 and 4.1.x before 4.1.1, when LDAP or HTTP is provided over SSL, uses world-readable permissions for a private key, which allows local users to obtain sensitive information by reading the key file, as demonstrated by access to the local filesystem on an AD domain controller.
Status
Package | Ubuntu Release | Status |
---|---|---|
samba | ||
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty |
Not affected
|
|
samba4 | ||
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
Notes
Patch details
Package | Patch details |
---|---|
samba4 |