HP CIFS 9000 Arbitrary Password Changing Vulnerability
BID:3250
Info
HP CIFS 9000 Arbitrary Password Changing Vulnerability
| Bugtraq ID: | 3250 |
| Class: | Environment Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 29 2001 12:00AM |
| Updated: | Aug 29 2001 12:00AM |
| Credit: | This vulnerability was announced in a HP Security Advisory on August 29, 2001. |
| Vulnerable: |
HP CIFS/9000 Server A.01.07 HP CIFS/9000 Server A.01.06 HP CIFS/9000 Server A.01.05 |
| Not Vulnerable: | |
Exploit / POC
HP CIFS 9000 Arbitrary Password Changing Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
HP CIFS 9000 Arbitrary Password Changing Vulnerability
Solution:
HP has advised customers to check their CIFS configuration files, and ensure the passwd program looks like the following:
passwd program = /bin/passwd %u
Solution:
HP has advised customers to check their CIFS configuration files, and ensure the passwd program looks like the following:
passwd program = /bin/passwd %u
References
HP CIFS 9000 Arbitrary Password Changing Vulnerability
References:
References: