Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:23913
HistoryApr 10, 2020 - 12:39 a.m.

Information Disclosure

2020-04-1000:39:58
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14

EPSS

0.001

Percentile

39.1%

Samba is vulnerable to Information Disclosure. The mount.cifs program printed CIFS passwords as part of its debug output when running in verbose mode. When mount.cifs had the setuid bit set, a local, unprivileged user could use this flaw to disclose passwords from a file that would otherwise be inaccessible to that user. Note: mount.cifs from the samba packages distributed by Red Hat does not have the setuid bit set. This flaw only affected systems where the setuid bit was manually set by an administrator.

References