Rapid7 Vulnerability & Exploit Database

Samba Easily Guessable New Password Weakness

Back to Search

Samba Easily Guessable New Password Weakness

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
Published
03/03/2004
Created
07/25/2018
Added
08/31/2007
Modified
05/27/2016

Description

The mksmbpasswd shell script (mksmbpasswd.sh) in Samba 3.0.0 and 3.0.1, when creating an account but marking it as disabled, may overwrite the user password with an uninitialized buffer, which could enable the account with a more easily guessable password.

Solution(s)

  • samba-upgrade-3_0_2

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;