CVE-2006-1059: Low severity Samba Samba vulnerability
The winbindd daemon in Samba 3.0.21 to 3.0.21c writes the machine trust account password in cleartext in log files, which allows local users to obtain the password and spoof the server in the domain.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-1059?
CVE-2006-1059 is classified as a moderate severity vulnerability due to potential local exploitation.
How do I fix CVE-2006-1059?
To fix CVE-2006-1059, you should upgrade to a newer version of Samba that does not log the machine trust account password in cleartext.
Which versions of Samba are affected by CVE-2006-1059?
CVE-2006-1059 affects Samba versions 3.0.21 to 3.0.21c.
What type of attack does CVE-2006-1059 allow?
CVE-2006-1059 allows local users to obtain the machine trust account password and potentially spoof the server.
How can I determine if my system is vulnerable to CVE-2006-1059?
You can check your Samba version and examine the log files for cleartext password entries to determine if your system is vulnerable to CVE-2006-1059.