CVE Database
/

CVE-2001-1106

Back to search

CVE-2001-1106

Published: Apr 2, 2003

Modified: Aug 8, 2024

PUBLISHED

Description

The default configuration of Sambar Server 5 and earlier uses a symmetric key that is compiled into the binary program for encrypting passwords, which could allow local users to break all user passwords by cracking the key or modifying a copy of the sambar program to call the decryption procedure.

VendorProductVersions

n/a

n/a

affected
n/a

References

3095
vdb-entry
x_refsource_BID
20010725 Sambar Server password decryption
mailing-list
x_refsource_BUGTRAQ
sambar-insecure-passwords(6909)
vdb-entry
x_refsource_XF

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now