HP CIFS/9000 Server (SAMBA) A.01.07 and earlier with the "unix password sync" option enabled calls the passwd program without specifying the username of the user making the request, which could cause the server to change the password of a different user.
References
Link | Resource |
---|---|
http://archives.neohapsis.com/archives/hp/2001-q3/0048.html | Patch Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/7051 | |
http://archives.neohapsis.com/archives/hp/2001-q3/0048.html | Patch Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/7051 |
Configurations
History
20 Nov 2024, 23:36
Type | Values Removed | Values Added |
---|---|---|
References | () http://archives.neohapsis.com/archives/hp/2001-q3/0048.html - Patch, Vendor Advisory | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/7051 - |
Information
Published : 2001-08-31 04:00
Updated : 2024-11-20 23:36
NVD link : CVE-2001-0981
Mitre link : CVE-2001-0981
CVE.ORG link : CVE-2001-0981
JSON object : View
Products Affected
hp
- cifs-9000_server
CWE