PT-2001-2132 · Hewlett Packard+1 · Hp Cifs/9000 Server+1

Published

2001-08-31

·

Updated

2017-10-10

·

CVE-2001-0981

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions HP CIFS/9000 Server (SAMBA) version A.01.07 and earlier
Description The issue arises when the "unix password sync" option is enabled, causing the server to potentially change the password of a different user due to the passwd program being called without specifying the username of the user making the request.
Recommendations For HP CIFS/9000 Server (SAMBA) version A.01.07 and earlier, consider disabling the "unix password sync" option until a fix is available to prevent potential password changes for unintended users.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-0981

Affected Products

Hp Cifs/9000 Server
Samba