---
title: "CVE-2013-0454\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2013-0454?format=md
keywords: index, follow
---

# CVE-2013-0454

Publication date 26 March 2013

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

The SMB2 implementation in Samba 3.6.x before 3.6.6, as used on the IBM
Storwize V7000 Unified 1.3 before 1.3.2.3 and 1.4 before 1.4.0.1 and
possibly other products, does not properly enforce CIFS share attributes,
which allows remote authenticated users to (1) write to a read-only share;
(2) trigger data-integrity problems related to the oplock, locking,
coherency, or leases attribute; or (3) have an unspecified impact by
leveraging incorrect handling of the browseable or "hide unreadable"
parameter.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| samba | 12.10 quantal | Not affected |
| 12.04 LTS precise | Fixed 2:3.6.3-2ubuntu2.6 |
| 11.10 oneiric | Not affected |
| 10.04 LTS lucid | Not affected |
| 8.04 LTS hardy | Not affected |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2013-0454?format=md#patch-details)

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| samba | * Upstream:   <http://git.samba.org/?p=samba.git;a=commit;h=15a423bf373a8116a0de7a627eaaea3932541e88> |

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0454)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2013-0454)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2013-0454)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2013-0454)

### Related Ubuntu Security Notices (USN)

+ [USN-1802-1](https://usn.ubuntu.com/USN-1802-1)
+ Samba vulnerability
+ 16 April 2013

### Other references

* <https://www.samba.org/samba/security/CVE-2013-0454>
* <https://lists.samba.org/archive/samba-announce/2012/000259.html>
* <http://xforce.iss.net/xforce/xfdb/80970>
* <http://www.ibm.com/support/docview.wss?uid=ssg1S1004289>
* <https://www.cve.org/CVERecord?id=CVE-2013-0454>
