PT-2004-1885 · Openldap+1 · Openldap+1

Published

2004-09-07

·

Updated

2017-10-11

·

CVE-2004-0823

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions OpenLDAP versions 1.0 through 2.1.19
Description The issue allows certain authentication schemes to use hashed (crypt) passwords in the userPassword attribute as if they were plaintext passwords. This enables remote attackers to re-use hashed passwords without decrypting them.
Recommendations For OpenLDAP versions 1.0 through 2.1.19, consider updating to a version where this issue is resolved, although the specific fixed version is not provided in the available data. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-0823
RHSA-2005:751
RHSA-2005_751

Affected Products

Openldap
Red Hat