|
Samba Machine Trust Account Local Information Disclosure Vulnerability
Samba is susceptible to a local information-disclosure vulnerability. This issue is due to a design error that potentially leads to sensitive information being written to log files. This occurs when the debugging level has been set to 5 or higher. This issue allows local attackers to gain access to the machine trust account of affected computers. Attackers may then impersonate the affected server in the domain. By impersonating the member server, attackers may gain access to further sensitive information, including the users and groups in the domain; other information may also be available. This may aid attackers in further attacks. Samba versions 3.0.21 through to 3.0.21c that use the 'winbindd' daemon are susceptible to this issue. |
|
|
Privacy Statement |