First published: Wed Oct 07 2009(Updated: )
mount.cifs in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8 and 3.4 before 3.4.2, when mount.cifs is installed suid root, does not properly enforce permissions, which allows local users to read part of the credentials file and obtain the password by specifying the path to the credentials file and using the --verbose or -v option.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Samba Samba | >=3.4.0<3.4.2 | |
Samba Samba | >=3.3.0<3.3.8 | |
Samba Samba | >=3.2.0<3.2.15 | |
Samba Samba | >=3.0.0<3.0.37 |
http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.561439
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.