Vulnerabilities > CVE-2005-2962 - Unspecified vulnerability in Ntlmaps

047910
CVSS 2.1 - LOW
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
local
low complexity
ntlmaps
nessus

Summary

The post-installation script for ntlmaps before 0.9.9 sets world-readable permissions for the configuration file, which allows local users to obtain the username and password.

Vulnerable Configurations

Part Description Count
Application
Ntlmaps
1

Nessus

NASL familyDebian Local Security Checks
NASL idDEBIAN_DSA-830.NASL
descriptionDrew Parsons noticed that the post-installation script of ntlmaps, an NTLM authorisation proxy server, changes the permissions of the configuration file to be world-readable. It contains the user name and password of the Windows NT system that ntlmaps connects to and, hence, leaks them to local users.
last seen2020-06-01
modified2020-06-02
plugin id19799
published2005-10-05
reporterThis script is Copyright (C) 2005-2019 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/19799
titleDebian DSA-830-1 : ntlmaps - wrong permissions