First published: Fri Aug 31 2001(Updated: )
HP CIFS/9000 Server (SAMBA) A.01.07 and earlier with the "unix password sync" option enabled calls the passwd program without specifying the username of the user making the request, which could cause the server to change the password of a different user.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Hp Cifs-9000 Server | <=a.01.07 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.