The default configuration of Sambar Server 5 and earlier uses a symmetric key that is compiled into the binary program for encrypting passwords, which could allow local users to break all user passwords by cracking the key or modifying a copy of the sambar program to call the decryption procedure.
Software | From | Fixed in |
---|---|---|
sambar / sambar_server | 4.1 | 4.1.x |
sambar / sambar_server | 4.2.1_production | 4.2.1_production.x |
sambar / sambar_server | 4.3 | 4.3.x |
sambar / sambar_server | 4.4 | 4.4.x |
sambar / sambar_server | 5.0-beta1 | 5.0-beta1.x |
sambar / sambar_server | 5.0-beta2 | 5.0-beta2.x |
sambar / sambar_server | 5.0-beta3 | 5.0-beta3.x |
sambar / sambar_server | 5.0-beta4 | 5.0-beta4.x |
sambar / sambar_server | 5.0-beta5 | 5.0-beta5.x |