Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Thomas Ptacek

#36839of 53,634
7.5Total CVSS
Vulnerabilities · 1
PT-2010-1619
7.5
2010-04-23
Integrity Scanner · Samhain · CVE-2009-4810
**Name of the Vulnerable Software and Affected Versions** Samhain versions prior to 2.5.4 **Description** The issue concerns the Secure Remote Password (SRP) implementation, which fails to check for a required zero value as specified by the protocol. This allows remote attackers to bypass authentication by providing crafted input. **Recommendations** For versions prior to 2.5.4, update to version 2.5.4 or later to resolve the issue.