LWN.net Logo

samba: multiple vulnerabilities

Package(s):samba CVE #(s):CVE-2011-2522 CVE-2011-2694
Created:July 27, 2011 Updated:September 23, 2011
Description: From the Mandriva advisory:

All current released versions of Samba are vulnerable to a cross-site request forgery in the Samba Web Administration Tool (SWAT). By tricking a user who is authenticated with SWAT into clicking a manipulated URL on a different web page, it is possible to manipulate SWAT (CVE-2011-2522).

All current released versions of Samba are vulnerable to a cross-site scripting issue in the Samba Web Administration Tool (SWAT). On the Change Password field, it is possible to insert arbitrary content into the user field (CVE-2011-2694).

Alerts:
CentOS CESA-2011:1220 2011-09-22
CentOS CESA-2011:1219 2011-09-22
openSUSE openSUSE-SU-2011:0998-1 2011-09-05
Pardus 2011-110 2011-09-05
Scientific Linux SL-samb-20110829 2011-08-29
Scientific Linux SL-samb-20110829 2011-08-29
Scientific Linux SL-Samb-20110829 2011-08-29
CentOS CESA-2011:1219 2011-08-29
Red Hat RHSA-2011:1221-01 2011-08-29
Red Hat RHSA-2011:1220-01 2011-08-29
Red Hat RHSA-2011:1219-01 2011-08-29
Fedora FEDORA-2011-10367 2011-08-05
Fedora FEDORA-2011-10341 2011-08-05
Debian DSA-2290-1 2011-08-07
Slackware SSA:2011-210-03 2011-08-01
Mandriva MDVSA-2011:121 2011-07-27
Ubuntu USN-1182-1 2011-08-02
Oracle ELSA-2012-0313 2012-03-07
SUSE SUSE-SU-2012:0348-1 2012-03-09

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds