MEDIUM
samba: clickjacking vulnerability in SWAT
Published Feb 2, 2013
5.1
MEDIUMCVSS 2.0
EPSS 3.25%
Description
The Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.21, 3.6.x before 3.6.12, and 4.x before 4.0.2 allows remote attackers to conduct clickjacking attacks via a (1) FRAME or (2) IFRAME element.
Affected products
No data.
Configuration 1
OR
- 3.0.0
- 3.0.1
- 3.0.2
- 3.0.2
- 3.0.2a
- 3.0.3
- 3.0.4
- 3.0.4
- 3.0.5
- 3.0.6
- 3.0.7
- 3.0.8
- 3.0.9
- 3.0.10
- 3.0.11
- 3.0.12
- 3.0.13
- 3.0.14
- 3.0.14
- 3.0.14a
- 3.0.15
- 3.0.16
- 3.0.17
- 3.0.18
- 3.0.19
- 3.0.20
- 3.0.20
- 3.0.20
- 3.0.20a
- 3.0.20b
- 3.0.21
- 3.0.21
- 3.0.21
- 3.0.21
- 3.0.21a
- 3.0.21b
- 3.0.21c
- 3.0.22
- 3.0.23
- 3.0.23
- 3.0.23
- 3.0.23
- 3.0.23
- 3.0.23a
- 3.0.23b
- 3.0.23c
- 3.0.23d
- 3.0.24
- 3.0.25
- 3.0.25
- 3.0.25
- 3.0.25
- 3.0.25
- 3.0.25
- 3.0.25
- 3.0.25
- 3.0.25
- 3.0.25a
- 3.0.25b
- 3.0.25c
- 3.0.26
- 3.0.26
- 3.0.26a
- 3.0.27
- 3.0.27
- 3.0.28
- 3.0.28
- 3.0.29
- 3.0.30
- 3.0.31
- 3.0.32
- 3.0.33
- 3.0.34
- 3.0.35
- 3.0.36
- 3.0.37
- 3.1.0
- 3.2.0
- 3.2.1
- 3.2.2
- 3.2.3
- 3.2.4
- 3.2.5
- 3.2.6
- 3.2.7
- 3.2.8
- 3.2.9
- 3.2.10
- 3.2.11
- 3.2.12
- 3.2.13
- 3.2.14
- 3.2.15
- 3.3.0
- 3.3.1
- 3.3.2
- 3.3.3
- 3.3.4
- 3.3.5
- 3.3.6
- 3.3.7
- 3.3.8
- 3.3.9
- 3.3.10
- 3.3.11
- 3.3.12
- 3.3.13
- 3.3.14
- 3.3.15
- 3.3.16
- 3.4.0
- 3.4.1
- 3.4.2
- 3.4.3
- 3.4.4
- 3.4.5
- 3.4.6
- 3.4.7
- 3.4.8
- 3.4.9
- 3.4.10
- 3.4.11
- 3.4.12
- 3.4.13
- 3.4.14
- 3.4.15
- 3.4.16
- 3.4.17
- 3.5.0
- 3.5.1
- 3.5.2
- 3.5.3
- 3.5.4
- 3.5.5
- 3.5.6
- 3.5.7
- 3.5.8
- 3.5.9
- 3.5.10
- 3.5.11
- 3.5.12
- 3.5.13
- 3.5.14
- 3.5.15
- 3.5.16
- 3.5.17
- 3.5.18
- 3.5.19
- 3.5.20
Configuration 2
OR
- 3.6.0
- 3.6.1
- 3.6.2
- 3.6.3
- 3.6.4
- 3.6.5
- 3.6.6
- 3.6.7
- 3.6.8
- 3.6.9
- 3.6.10
- 3.6.11
No data.
Red Hat Enterprise Linux 5
samba-0:3.0.33-3.40.el5_10
Fixed · RHSA-2014:0305
Red Hat Enterprise Linux 5
samba3x-0:3.6.6-0.136.el5
Fixed · RHSA-2013:1310
Red Hat Enterprise Linux 6
samba-0:3.6.9-164.el6
Fixed · RHSA-2013:1542
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | samba-0:3.0.33-3.40.el5_10 | Fixed | RHSA-2014:0305 |
| Red Hat Enterprise Linux 5 | samba3x-0:3.6.6-0.136.el5 | Fixed | RHSA-2013:1310 |
| Red Hat Enterprise Linux 6 | samba-0:3.6.9-164.el6 | Fixed | RHSA-2013:1542 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (17)
- http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00019.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00042.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-updates/2013-02/msg00029.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-updates/2013-02/msg00033.html vendor-advisoryx_refsource_SUSE
- http://rhn.redhat.com/errata/RHSA-2013-1310.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2013-1542.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2014-0305.html vendor-advisoryx_refsource_REDHAT
- http://www.debian.org/security/2013/dsa-2617 vendor-advisoryx_refsource_DEBIAN
- http://www.samba.org/samba/security/CVE-2013-0213 x_refsource_CONFIRMVendor Advisory
- http://www.securityfocus.com/bid/57631 vdb-entryx_refsource_BID
- http://www.ubuntu.com/usn/USN-2922-1 vendor-advisoryx_refsource_UBUNTU
- https://access.redhat.com/security/cve/CVE-2013-0213 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=905700 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-0247 Advisory
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05115993 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2013-0213
- https://www.cve.org/CVERecord?id=CVE-2013-0213
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Feb 2, 2013
Updated Aug 6, 2024
Reserved Dec 6, 2012
Link CVE-2013-0213
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2013-0247 Assigner redhat
Published Feb 2, 2013
Updated Aug 6, 2024
Exploited since n/a
Link EUVD-2013-0247