Displaying 1 result from an estimated 1 matches for "samrchangepassword".
2007 May 14
0
[SAMBA-SECURITY] CVE-2007-2447: Remote Command Injection Vulnerability
...aped user input parameters are passed
== as arguments to /bin/sh allowing for remote
== command execution
==
==========================================================
===========
Description
===========
This bug was originally reported against the anonymous calls
to the SamrChangePassword() MS-RPC function in combination
with the "username map script" smb.conf option (which is not
enabled by default).
After further investigation by Samba developers, it was
determined that the problem was much broader and impacts
remote printer and file share management as well. The root...