suse · CVE-2013-4476

Quick triage

Priority: low Published: 2021-05-30 13:14:28 UTC Updated: 2026-04-18 18:52:50 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2013-4476 severity low: SUSE including 523 source package names (ctdb-4.10.5+git.129.35f7bb6e177-1.1, ctdb-4.22.3+git.401.c70158430cc-160000.2.2, …), 868 product×package rows across 26 product lines (SUSE Linux Enterprise Desktop 12, SUSE Linux Enterprise Desktop 12 SP1, … (26 product lines)): Fixed 868.

Description:

Samba 4.0.x before 4.0.11 and 4.1.x before 4.1.1, when LDAP or HTTP is provided over SSL, uses world-readable permissions for a private key, which allows local users to obtain sensitive information by reading the key file, as demonstrated by access to the local filesystem on an AD domain controller.

cvelogic Threat Intelligence