jCIFS SmbSession Unauthorized Access Vulnerability
BID:6977
Info
jCIFS SmbSession Unauthorized Access Vulnerability
| Bugtraq ID: | 6977 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Feb 28 2003 12:00AM |
| Updated: | Feb 28 2003 12:00AM |
| Credit: | This vulnerability was reported in the product changelog. |
| Vulnerable: |
jCIFS jCIFS 0.7.2 jCIFS jCIFS 0.7.1 jCIFS jCIFS 0.7 0b5 jCIFS jCIFS 0.7 jCIFS jCIFS 0.6.8 jCIFS jCIFS 0.6.6 |
| Not Vulnerable: |
jCIFS jCIFS 0.7.3 |
Discussion
jCIFS SmbSession Unauthorized Access Vulnerability
It has been reported that the jCIFS API is prone to a condition where, under certain circumstances, a user supplying password credentials may be authenticated to a network share without sufficient checks.
This may result in an attacker gaining unauthorized access to SMB network shares.
It has been reported that the jCIFS API is prone to a condition where, under certain circumstances, a user supplying password credentials may be authenticated to a network share without sufficient checks.
This may result in an attacker gaining unauthorized access to SMB network shares.
Exploit / POC
jCIFS SmbSession Unauthorized Access Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
jCIFS SmbSession Unauthorized Access Vulnerability
Solution:
Fixes available:
jCIFS jCIFS 0.6.6
jCIFS jCIFS 0.6.8
jCIFS jCIFS 0.7
jCIFS jCIFS 0.7 0b5
jCIFS jCIFS 0.7.1
jCIFS jCIFS 0.7.2
Solution:
Fixes available:
jCIFS jCIFS 0.6.6
-
jCIFS jcifs-0.7.3
http://users.erols.com/mballen/jcifs/
jCIFS jCIFS 0.6.8
-
jCIFS jcifs-0.7.3
http://users.erols.com/mballen/jcifs/
jCIFS jCIFS 0.7
-
jCIFS jcifs-0.7.3
http://users.erols.com/mballen/jcifs/
jCIFS jCIFS 0.7 0b5
-
jCIFS jcifs-0.7.3
http://users.erols.com/mballen/jcifs/
jCIFS jCIFS 0.7.1
-
jCIFS jcifs-0.7.3
http://users.erols.com/mballen/jcifs/
jCIFS jCIFS 0.7.2
-
jCIFS jcifs-0.7.3
http://users.erols.com/mballen/jcifs/