---
title: "CVE-2011-2694\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2011-2694?format=md
keywords: index, follow
---

# CVE-2011-2694

Publication date 28 July 2011

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Cross-site scripting (XSS) vulnerability in the chg\_passwd function in
web/swat.c in the Samba Web Administration Tool (SWAT) in Samba 3.x before
3.5.10 allows remote authenticated administrators to inject arbitrary web
script or HTML via the username parameter to the passwd program (aka the
user field to the Change Password page).

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| samba | 11.04 natty | Fixed 2:3.5.8~dfsg-1ubuntu2.3 |
| 10.10 maverick | Fixed 2:3.5.4~dfsg-1ubuntu8.5 |
| 10.04 LTS lucid | Fixed 2:3.4.7~dfsg-1ubuntu3.7 |
| 8.04 LTS hardy | Fixed 3.0.28a-1ubuntu4.15 |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2011-2694?format=md#patch-details)

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| samba | * Upstream:   <http://ftp.samba.org/pub/samba/patches/security/> |

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2694)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2011-2694)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2011-2694)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2011-2694)

### Related Ubuntu Security Notices (USN)

+ [USN-1182-1](https://usn.ubuntu.com/USN-1182-1)
+ Samba vulnerabilities
+ 2 August 2011

### Other references

* <http://www.samba.org/samba/security/CVE-2011-2694>
* <https://www.cve.org/CVERecord?id=CVE-2011-2694>
