Fedora Account System
Red Hat Associate
Red Hat Customer
Samba clear text password exposure The following text was taken from the samba advisory: The machine trust account password is the secret shared between a domain controller and a specific member server. Access to the member server machine credentials may allow an attacker to access additional information regarding user accounts in the domain. The winbindd daemon included in Samba 3.0.21 and subsequent patch releases (3.0.21a-c) writes the clear text of server's machine credentials to its log file at level 5. The winbindd log files are world readable by default and often log files are requested on open mailing lists as tools used to debug server misconfigurations. Please note our samba log files are stored in a directory which is only readable by root.
This issue is now public: http://us2.samba.org/samba/news/#3.0.22
samba-3.0.22-1.fc5 has been pushed for FC5, which should resolve this issue. If these problems are still present in this version, then please make note of it in this bug report.