The mksmbpasswd shell script (mksmbpasswd.sh) in Samba 3.0.0 and 3.0.1, when creating an account but marking it as disabled, may overwrite the user password with an uninitialized buffer, which could enable the account with a more easily guessable password.
References
Configurations
Configuration 1 (hide)
|
History
20 Nov 2024, 23:47
Type | Values Removed | Values Added |
---|---|---|
References | () http://us1.samba.org/samba/ftp/WHATSNEW-3.0.2a.txt - | |
References | () http://www.ciac.org/ciac/bulletins/o-078.shtml - | |
References | () http://www.osvdb.org/3919 - | |
References | () http://www.redhat.com/support/errata/RHSA-2004-064.html - Patch, Vendor Advisory | |
References | () http://www.securityfocus.com/bid/9637 - Patch, Vendor Advisory | |
References | () http://www.vuxml.org/freebsd/3388eff9-5d6e-11d8-80e3-0020ed76ef5a.html - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/15132 - | |
References | () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A827 - |
Information
Published : 2004-03-03 05:00
Updated : 2024-11-20 23:47
NVD link : CVE-2004-0082
Mitre link : CVE-2004-0082
CVE.ORG link : CVE-2004-0082
JSON object : View
Products Affected
samba
- samba
CWE