PT-2014-8408 · Zend · Zend

Publicado

2014-10-22

·

Atualizado

2022-05-17

·

CVE-2014-8088

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Zend versions prior to 1.12.9 Zend 2.x versions prior to 2.2.8 Zend 2.3.x versions prior to 2.3.3
Description The issue allows remote attackers to bypass authentication through a password starting with a null byte, triggering an unauthenticated bind. This occurs due to a flaw in the Zend Ldap class and the ZendLdap component.
Recommendations For versions prior to 1.12.9, update to version 1.12.9 or later. For Zend 2.x versions prior to 2.2.8, update to version 2.2.8 or later. For Zend 2.3.x versions prior to 2.3.3, update to version 2.3.3 or later.

Exploit

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-8088
DLA-251-1
DSA-3265-1
DSA-3265-2
GHSA-F6RC-RH43-H8GR
MGASA-2014-0434

Produtos afetados

Zend