Title : Samba "winbindd" Machine Trust Account Password Disclosure Vulnerability VUPEN ID : VUPEN/ADV-2006-1179 CVE ID : CVE-2006-1059
Rated as : Low Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2006-03-30
Technical Description
A vulnerability has been identified in Samba, which could be exploited by malicious users to disclose sensitive information. This flaw is due to an error in the "winbindd" daemon that writes the machine trust account password to world-readable log files in clear text, which could be exploited by local attackers to bypass security restrictions and gain knowledge of sensitive information.