[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2004-0823Date: (C)2004-09-07   (M)2023-12-22


OpenLDAP 1.0 through 2.1.19, as used in Apple Mac OS 10.3.4 and 10.3.5 and possibly other operating systems, may allow certain authentication schemes to use hashed (crypt) passwords in the userPassword attribute as if they were plaintext passwords, which allows remote attackers to re-use hashed passwords without decrypting them.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 7.5
Exploit Score: 10.0
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
BID-11137
SECUNIA-12491
SECUNIA-17233
SECUNIA-21520
APPLE-SA-2004-09-07
ESB-2004.0559
RHSA-2005:751
http://support.avaya.com/elmodocs2/security/ASA-2006-157.htm
openldap-crypt-gain-access(17300)
oval:org.mitre.oval:def:10703

CPE    6
cpe:/o:apple:mac_os_x_server:10.3.5
cpe:/o:apple:mac_os_x:10.2.8
cpe:/o:apple:mac_os_x_server:10.3.4
cpe:/o:apple:mac_os_x_server:10.2.8
...

© SecPod Technologies