7.5
CVSSv2

CVE-2004-0823

Published: 07/09/2004 Updated: 11/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

OpenLDAP 1.0 up to and including 2.1.19, as used in Apple Mac OS 10.3.4 and 10.3.5 and possibly other operating systems, may allow certain authentication schemes to use hashed (crypt) passwords in the userPassword attribute as if they were plaintext passwords, which allows remote malicious users to re-use hashed passwords without decrypting them.

Vulnerable Product Search on Vulmon Subscribe to Product

openldap openldap 1.1

openldap openldap 1.1.1

openldap openldap 1.2.12

openldap openldap 1.2.13

openldap openldap 1.2.8

openldap openldap 1.2.9

openldap openldap 1.0

openldap openldap 1.0.1

openldap openldap 1.1.4

openldap openldap 1.2

openldap openldap 1.2.4

openldap openldap 1.2.5

openldap openldap 2.0.10

openldap openldap 2.0.11

openldap openldap 2.0.15

openldap openldap 2.0.16

openldap openldap 2.0.17

openldap openldap 2.0.23

openldap openldap 2.0.25

openldap openldap 2.0.8

openldap openldap 2.0.9

openldap openldap 2.1.17

openldap openldap 2.1.18

openldap openldap 1.1.2

openldap openldap 1.1.3

openldap openldap 1.2.2

openldap openldap 1.2.3

openldap openldap 2.0

openldap openldap 2.0.1

openldap openldap 2.0.13

openldap openldap 2.0.14

openldap openldap 2.0.21

openldap openldap 2.0.22

openldap openldap 2.0.6

openldap openldap 2.0.7

openldap openldap 2.1.14

openldap openldap 2.1.15

openldap openldap 2.1.16

openldap openldap 2.0.11_9

openldap openldap 2.0.12

openldap openldap 2.0.2

openldap openldap 2.0.20

openldap openldap 2.0.4

openldap openldap 2.0.5

openldap openldap 2.1.12

openldap openldap 2.1.13

openldap openldap 2.1_.20

openldap openldap 1.0.2

openldap openldap 1.0.3

openldap openldap 1.2.1

openldap openldap 1.2.10

openldap openldap 1.2.11

openldap openldap 1.2.6

openldap openldap 1.2.7

openldap openldap 2.0.11_11

openldap openldap 2.0.11_11s

openldap openldap 2.0.18

openldap openldap 2.0.19

openldap openldap 2.0.27

openldap openldap 2.0.3

openldap openldap 2.1.10

openldap openldap 2.1.11

openldap openldap 2.1.19

openldap openldap 2.1.4

apple mac os x 10.3.5

apple mac os x server 10.2.8

apple mac os x 10.2.8

apple mac os x 10.3.4

apple mac os x server 10.3.4

apple mac os x server 10.3.5

Vendor Advisories

Synopsis openldap and nss_ldap security update Type/Severity Security Advisory: Moderate Topic Updated openldap and nss_ldap packages that correct a potential password disclosure issue are now availableThis update has been rated as having moderate security impact by the Red Hat Security Response Team ...