Smb4K before 1.1.1 allows remote attackers to obtain credentials via vectors related to the cuid option in the Additional options line edit.
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Smb4k | Smb4k_project | * | 1.1.1 (excluding) |
Smb4k | Ubuntu | artful | * |
Smb4k | Ubuntu | lucid | * |
Smb4k | Ubuntu | precise | * |
Smb4k | Ubuntu | quantal | * |
Smb4k | Ubuntu | saucy | * |
Smb4k | Ubuntu | trusty | * |
Smb4k | Ubuntu | upstream | * |
Smb4k | Ubuntu | utopic | * |
Smb4k | Ubuntu | vivid | * |
Smb4k | Ubuntu | wily | * |
Smb4k | Ubuntu | xenial | * |
Smb4k | Ubuntu | yakkety | * |
Smb4k | Ubuntu | zesty | * |