HP CIFS/9000 Server (SAMBA) A.01.07 and earlier with the "unix password sync" option enabled calls the passwd program without specifying the username of the user making the request, which could cause the server to change the password of a different user.
References
Link | Resource |
---|---|
http://archives.neohapsis.com/archives/hp/2001-q3/0048.html | Patch Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/7051 |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2002-06-25T04:00:00
Updated: 2002-06-16T00:00:00
Reserved: 2002-01-31T00:00:00
Link: CVE-2001-0981
JSON object: View
NVD Information
Status : Modified
Published: 2001-08-31T04:00:00.000
Modified: 2017-10-10T01:29:57.483
Link: CVE-2001-0981
JSON object: View
Redhat Information
No data.
CWE