Samba 4.0.x before 4.0.11 and 4.1.x before 4.1.1, when LDAP or HTTP is provided over SSL, uses world-readable permissions for a private key, which allows local users to obtain sensitive information by reading the key file, as demonstrated by access to the local filesystem on an AD domain controller.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2013-11-13T15:00:00

Updated: 2024-08-06T16:45:14.706Z

Reserved: 2013-06-12T00:00:00

Link: CVE-2013-4476

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2013-11-13T15:55:03.517

Modified: 2024-11-21T01:55:38.760

Link: CVE-2013-4476

cve-icon Redhat

Severity : Moderate

Publid Date: 2013-11-11T00:00:00Z

Links: CVE-2013-4476 - Bugzilla