Smb4K before 1.1.1 allows remote attackers to obtain credentials via vectors related to the cuid option in the "Additional options" line edit.
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Link | Tags |
---|---|
http://sourceforge.net/projects/smb4k/files/1.1.1/ | third party advisory release notes |
http://www.openwall.com/lists/oss-security/2014/03/24/1 | third party advisory mailing list |
http://www.openwall.com/lists/oss-security/2014/03/25/5 | third party advisory mailing list |
http://lists.fedoraproject.org/pipermail/package-announce/2014-June/133898.html | third party advisory mailing list |
http://lists.fedoraproject.org/pipermail/package-announce/2014-June/133901.html | third party advisory mailing list |
https://bugs.gentoo.org/505376 | patch third party advisory issue tracking |