Multiple cross-site request forgery (CSRF) vulnerabilities in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allow remote attackers to hijack the authentication of administrators for requests that (1) shut down daemons, (2) start daemons, (3) add shares, (4) remove shares, (5) add printers, (6) remove printers, (7) add user accounts, or (8) remove user accounts, as demonstrated by certain start, stop, and restart parameters to the status program.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade samba3x-docUpgrade samba3x-domainjoin-guiUpgrade samba3x-commonUpgrade samba3x-winbind-develUpgrade samba3xUpgrade samba3x-clientUpgrade samba-clientUpgrade libsmbclient-develUpgrade sambaUpgrade samba3x-swatUpgrade samba-swatUpgrade samba-commonUpgrade libsmbclientUpgrade samba3x-winbind | Dec 1, 2016 | Jul 29, 2011 |
| Debian | — | Upgrade samba | Jul 30, 2024 | Jul 29, 2011 |
| Freebsd | — | Upgrade samba35Upgrade samba34 | Dec 10, 2025 | Aug 16, 2011 |
| Hpux | — | Update CIFS-Server.CIFS-LIB to the latest versionUpdate CIFS-Server.CIFS-ADMIN to the latest versionUpdate CIFS-Server.CIFS-UTIL to the latest versionUpdate CIFS-Server.CIFS-DOC to the latest versionUpdate CIFS-CFSM.CFSM-RUN to the latest versionUpdate CIFS-Development.CIFS-PRG to the latest versionUpdate CIFS-Server.CIFS-RUN to the latest versionUpdate CIFS-CFSM.CFSM-KRN to the latest version | Aug 11, 2017 | Jul 29, 2011 |
| Oracle_linux | — | Upgrade samba-winbind-clientsUpgrade samba-winbind-krb5-locatorUpgrade samba3x-domainjoin-guiUpgrade cifs-utilsUpgrade samba-winbind-develUpgrade libsmbclient-develUpgrade samba3x-winbind-develUpgrade samba-commonUpgrade samba-clientUpgrade samba-domainjoin-guiUpgrade samba3x-docUpgrade samba3x-commonUpgrade samba3x-winbindUpgrade samba3x-swatUpgrade samba-swatUpgrade sambaUpgrade samba3xUpgrade samba3x-clientUpgrade libsmbclientUpgrade samba-docUpgrade samba-winbind | Oct 16, 2024 | Jul 29, 2011 |
| Samba | — | Upgrade to Samba version 3.5.10Upgrade to Samba version 3.3.16Upgrade to Samba version 3.4.14 | Nov 13, 2013 | Jul 29, 2011 |
| Suse | — | Upgrade samba-winbind-x86Upgrade libtalloc2-32bitUpgrade samba-winbindUpgrade libwbclient-develUpgrade libwbclient0-32bitUpgrade libmsrpc-develUpgrade cifs-mountUpgrade samba-docUpgrade libsmbclient-64bitUpgrade sambaUpgrade samba-32bitUpgrade libsmbclientUpgrade libldb-develUpgrade libtevent-develUpgrade libtalloc2Upgrade samba-x86Upgrade sap-aio-releaseUpgrade ldapsmbUpgrade samba-winbind-32bitUpgrade libtalloc-develUpgrade libsmbclient-32bitUpgrade samba-pythonUpgrade libtevent0Upgrade libtdb1Upgrade libldb0Upgrade libsmbsharemodes-develUpgrade libtdb1-32bitUpgrade samba-vscanUpgrade libsmbclient0Upgrade samba-client-32bitUpgrade libtdb-develUpgrade libsmbclient0-32bitUpgrade libmsrpcUpgrade samba-pdbUpgrade samba-develUpgrade samba-krb-printingUpgrade samba-64bitUpgrade libsmbclient-x86Upgrade libsmbsharemodesUpgrade samba-clientUpgrade libsmbsharemodes0Upgrade libsmbclient-develUpgrade samba-client-x86Upgrade samba-client-64bitUpgrade libwbclient0Upgrade samba-winbind-64bitUpgrade libnetapi0Upgrade libnetapi-devel | Dec 12, 2013 | Jul 29, 2011 |
| Ubuntu | — | Upgrade swat | Nov 8, 2024 | Jul 29, 2011 |
| Vmsa 2012 0001 | — | Upgrade VMware ESX 4.1 to build number 582267Upgrade VMware ESX 4.0 to build number 660575 | Feb 3, 2012 | Jul 29, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub