Secunia Logo
 
CVE Reference: CVE-2004-0823
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2004-0823

Description:
OpenLDAP 1.0 through 2.1.19, as used in Apple Mac OS 10.3.4 and 10.3.5 and possibly other operating systems, may allow certain authentication schemes to use hashed (crypt) passwords in the userPassword attribute as if they were plaintext passwords, which allows remote attackers to re-use hashed passwords without decrypting them.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/17300

SAID
  Secunia Advisory: SA17233
  Secunia Advisory: SA12491
  Secunia Advisory: SA21520

REDHAT
  http://www.redhat.com/support/errata/RHSA-2005-751.html

CONFIRM
  http://support.avaya.com/elmodocs2/security/ASA-2006-157.htm

BID
  11137

AUSCERT
  http://www.auscert.org.au/render.html?it=4363

APPLE
  http://www.securityfocus.com/advisories/7148


Return to the previous page.