5.1
CVSSv2

CVE-2010-2940

Published: 30/08/2010 Updated: 17/08/2017
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 454
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

The auth_send function in providers/ldap/ldap_auth.c in System Security Services Daemon (SSSD) 1.3.0, when LDAP authentication and anonymous bind are enabled, allows remote malicious users to bypass the authentication requirements of pam_authenticate via an empty password.

Vulnerable Product Search on Vulmon Subscribe to Product

fedoraproject sssd 1.3.0

Vendor Advisories

Debian Bug report logs - #594413 CVE-2010-2940: allows null password entry to authenticate against LDAP Package: sssd; Maintainer for sssd is Debian SSSD Team <pkg-sssd-devel@alioth-listsdebiannet>; Source for sssd is src:sssd (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Wed, 25 Aug ...