First published: Tue Dec 19 2000(Updated: )
Samba Web Administration Tool (SWAT) in Samba 2.0.7 installs the cgi.log logging file with world readable permissions, which allows local users to read sensitive information such as user names and passwords.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Samba | =2.0.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0936 is considered a moderate severity vulnerability due to the potential exposure of sensitive information.
To fix CVE-2000-0936, you should change the permissions of the cgi.log file to restrict access only to authorized users.
CVE-2000-0936 affects Samba version 2.0.7 specifically.
CVE-2000-0936 can expose sensitive information such as usernames and passwords stored in the cgi.log file.
Although CVE-2000-0936 was identified over two decades ago, any systems still running affected versions of Samba remain at risk if not patched.