HP CIFS/9000 Server (SAMBA) A.01.07 and earlier with the "unix password sync" option enabled calls the passwd program without specifying the username of the user making the request, which could cause the server to change the password of a different user.
References
Link | Resource |
---|---|
http://archives.neohapsis.com/archives/hp/2001-q3/0048.html | Patch Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/7051 |
Configurations
Information
Published : 2001-08-30 21:00
Updated : 2017-10-09 18:29
NVD link : CVE-2001-0981
Mitre link : CVE-2001-0981
JSON object : View
CWE
Products Affected
hp
- cifs-9000_server