CVE-2006-1059
Summary
| CVE | CVE-2006-1059 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-03-30 17:06:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | The winbindd daemon in Samba 3.0.21 to 3.0.21c writes the machine trust account password in cleartext in log files, which allows local users to obtain the password and spoof the server in the domain. |
Risk And Classification
Primary CVSS: v2.0 1.2 from [email protected]
AV:L/AC:H/Au:N/C:P/I:N/A:N
EPSS: 0.004560000 probability, percentile 0.639370000 (date 2026-04-19)
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
HighAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:L/AC:H/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.osvdb.org/24263 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| www.trustix.org/errata/2006/0018 | af854a3a-2127-422b-91ae-364da2661108 | www.trustix.org | |
| Samba Machine Trust Account Local Information Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| SecurityTracker.com Archives - Samba winbindd Daemon Discloses Server Password to Local Users | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| [SECURITY] Fedora Core 5 Update: samba-3.0.22-1.fc5 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Secunia - Advisories - Trustix update for samba | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Secunia - Advisories - Fedora update for samba | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Samba - Security Announcement Archive | af854a3a-2127-422b-91ae-364da2661108 | us1.samba.org | Patch |
| Samba Exposure of Machine Account Credentials - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Patch, Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.