DSA-2096-1 zope-ldapuserfolder -- missing input validation

Related Vulnerabilities: CVE-2010-2944  

Jeremy James discovered that in LDAPUserFolder, a Zope extension used to authenticate against an LDAP server, the authentication code does not verify the password provided for the emergency user. Malicious users that manage to get the emergency user login can use this flaw to gain administrative access to the Zope instance, by providing an arbitrary password. For the stable distribution (lenny), this problem has been fixed in version 2.9-1+lenny1. The package no longer exists in the upcoming stable distribution (squeeze) or the unstable distribution. We recommend that you upgrade your zope-ldapuserfolder package.

Debian Security Advisory

DSA-2096-1 zope-ldapuserfolder -- missing input validation

Date Reported:
24 Aug 2010
Affected Packages:
zope-ldapuserfolder
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 593466.
In Mitre's CVE dictionary: CVE-2010-2944.
More information:

Jeremy James discovered that in LDAPUserFolder, a Zope extension used to authenticate against an LDAP server, the authentication code does not verify the password provided for the emergency user. Malicious users that manage to get the emergency user login can use this flaw to gain administrative access to the Zope instance, by providing an arbitrary password.

For the stable distribution (lenny), this problem has been fixed in version 2.9-1+lenny1.

The package no longer exists in the upcoming stable distribution (squeeze) or the unstable distribution.

We recommend that you upgrade your zope-ldapuserfolder package.

Fixed in:

Debian GNU/Linux 5.0 (lenny)

Source:
http://security.debian.org/pool/updates/main/z/zope-ldapuserfolder/zope-ldapuserfolder_2.9.orig.tar.gz
http://security.debian.org/pool/updates/main/z/zope-ldapuserfolder/zope-ldapuserfolder_2.9-1+lenny1.dsc
http://security.debian.org/pool/updates/main/z/zope-ldapuserfolder/zope-ldapuserfolder_2.9-1+lenny1.diff.gz
Architecture-independent component:
http://security.debian.org/pool/updates/main/z/zope-ldapuserfolder/zope-ldapuserfolder_2.9-1+lenny1_all.deb

MD5 checksums of the listed files are available in the original advisory.