First published: Thu Mar 30 2006(Updated: )
The winbindd daemon in Samba 3.0.21 to 3.0.21c writes the machine trust account password in cleartext in log files, which allows local users to obtain the password and spoof the server in the domain.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samba | =3.0.21 | |
Samba | =3.0.21a | |
Samba | =3.0.21b | |
Samba | =3.0.21c |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-1059 is classified as a moderate severity vulnerability due to potential local exploitation.
To fix CVE-2006-1059, you should upgrade to a newer version of Samba that does not log the machine trust account password in cleartext.
CVE-2006-1059 affects Samba versions 3.0.21 to 3.0.21c.
CVE-2006-1059 allows local users to obtain the machine trust account password and potentially spoof the server.
You can check your Samba version and examine the log files for cleartext password entries to determine if your system is vulnerable to CVE-2006-1059.