Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 492
Alerts This Week
Warning Icon 1 492

SUSE: 2013:0325-1 Important: Click-jacking and CSRF Fixes

suse
Calendar Grey February 22, 2013
Scroller Suse
Fixes address two vulnerabilities in Samba that affect SUSE platforms. Critical patches are now provided for the versions in question.
An update that solves two vulnerabilities and has three An update that solves two vulnerabilities and has three An update that solves two vulnerabilities and has three fixes is now...

Summary

The Samba Web Administration Tool (SWAT) in Samba versions 3.0.x to 4.0.1 was affected by a cross-site request forgery (CVE-2013-0214) and a click-jacking attack (CVE-2013-0213). This has been fixed. Additionally a bug in mount.cifs has been fixed which could have lead to file disclosure (CVE-2012-1586). Also a uninitialized memory read bug in talloc_free() has been fixed. (bnc#764577). Security Issue references: * CVE-2013-0213 * CVE-2013-0214 Package List: - SUSE Linux Enterprise Server 10 SP4 (i586 ia64 ppc s390x x86_64): cifs-mount-3.0.36-0.13.24.1 ldapsmb-1.34b-25.13.24.1 libmsrpc-3.0.36-0.13.24.1 libmsrpc-devel-3.0.36-0.13.24.1

References

#754443 #764577 #783384 #799641 #800982

Cross- CVE-2013-0213 CVE-2013-0214

Affected Products:

SUSE Linux Enterprise Server 10 SP4

SUSE Linux Enterprise Desktop 10 SP4

SLE SDK 10 SP4

https://www.suse.com/security/cve/CVE-2013-0213.html

https://www.suse.com/security/cve/CVE-2013-0214.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2013:0325-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.