First published: Tue Dec 19 2000(Updated: )
Samba Web Administration Tool (SWAT) in Samba 2.0.7 supplies a different error message when a valid username is provided versus an invalid name, which allows remote attackers to identify valid users on the server.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Samba | =2.0.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0938 has a moderate severity due to its potential for user enumeration.
To fix CVE-2000-0938, upgrade Samba to a version later than 2.0.7.
CVE-2000-0938 is a vulnerability in Samba 2.0.7 that allows remote attackers to identify valid usernames through differing error messages.
Users running Samba version 2.0.7 are affected by CVE-2000-0938.
Yes, CVE-2000-0938 can facilitate further attacks by allowing attackers to know valid usernames.