CVE-2013-4475: Canonical Ubuntu Linux

Medium severity, CVSS 4.0. EPSS: 9% chance of exploitation in the next 30 days.

Samba 3.2.x through 3.6.x before 3.6.20, 4.0.x before 4.0.11, and 4.1.x before 4.1.1, when vfs_streams_depot or vfs_streams_xattr is enabled, allows remote attackers to bypass intended file restrictions by leveraging ACL differences between a file and an associated alternate data stream (ADS).

Affected products

  • Canonical Ubuntu Linux: version 10.04 only; version 12.04 only; version 12.10 only; version 13.04 only; version 13.10 only
  • Debian Debian Linux: version 6.0 only; version 7.0 only
  • Samba Samba: from 3.2.0, before 3.6.20 (fixed in 3.6.20); from 4.0.0, before 4.0.11 (fixed in 4.0.11); version 4.1.0 only

Published 2013-11-13. Last modified 2026-06-16.