|
|
Log in / Subscribe / Register

samba: clear text password exposure

Package(s):samba CVE #(s):CVE-2006-1059
Created:March 31, 2006 Updated:April 4, 2006
Description: According to this Samba advisory the winbindd daemon included in Samba 3.0.21 and subsequent patch releases (3.0.21a-c) writes the clear text of server's machine credentials to its log file at level 5. The winbindd log files are world readable by default and often log files are requested on open mailing lists as tools used to debug server misconfigurations. This vulnerability has been fixed in Samba 3.0.22.
Alerts:
Fedora FEDORA-2006-259 samba 2006-03-30

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds