jCIFS Invalid Username Authentication Bypass Weakness
BID:10494
Info
jCIFS Invalid Username Authentication Bypass Weakness
| Bugtraq ID: | 10494 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 01 2004 12:00AM |
| Updated: | Jun 01 2004 12:00AM |
| Credit: | Sebastian Rehbach originally notified the vendor. |
| Vulnerable: |
jCIFS jCIFS 0.9 .0b jCIFS jCIFS 0.9 .0 jCIFS jCIFS 0.8.3 jCIFS jCIFS 0.8.2 jCIFS jCIFS 0.8.1 jCIFS jCIFS 0.7.3 jCIFS jCIFS 0.7.2 jCIFS jCIFS 0.7.1 jCIFS jCIFS 0.7 0b5 jCIFS jCIFS 0.7 jCIFS jCIFS 0.6.8 jCIFS jCIFS 0.6.6 |
| Not Vulnerable: |
jCIFS jCIFS 0.9.2 jCIFS jCIFS 0.9.1 |
Discussion
jCIFS Invalid Username Authentication Bypass Weakness
It has been reported that jCIFS improperly allows authentication to succeed with an invalid username, when connecting to a CIFS server which has the guest account enabled.
This may allow an attacker unauthorized access to the CIFS server, potentially disclosing sensitive information.
Versions prior to 0.9.1 are reported vulnerable to this issue.
It has been reported that jCIFS improperly allows authentication to succeed with an invalid username, when connecting to a CIFS server which has the guest account enabled.
This may allow an attacker unauthorized access to the CIFS server, potentially disclosing sensitive information.
Versions prior to 0.9.1 are reported vulnerable to this issue.
Exploit / POC
jCIFS Invalid Username Authentication Bypass Weakness
No exploit is required.
No exploit is required.
Solution / Fix
jCIFS Invalid Username Authentication Bypass Weakness
Solution:
The vendor has released an upgraded version which addresses this issue.
Solution:
The vendor has released an upgraded version which addresses this issue.
References
jCIFS Invalid Username Authentication Bypass Weakness
References:
References:
- jCIFS Homepage (jCIFS)
- jcifs-0.9.1 released / Security Update (Michael B Allen)