CVE Vulnerabilities

CVE-2004-0823

Published: Sep 07, 2004 | Modified: Oct 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

OpenLDAP 1.0 through 2.1.19, as used in Apple Mac OS 10.3.4 and 10.3.5 and possibly other operating systems, may allow certain authentication schemes to use hashed (crypt) passwords in the userPassword attribute as if they were plaintext passwords, which allows remote attackers to re-use hashed passwords without decrypting them.

Affected Software

Name Vendor Start Version End Version
Openldap Openldap 1.0 (including) 1.0 (including)
Openldap Openldap 1.0.1 (including) 1.0.1 (including)
Openldap Openldap 1.0.2 (including) 1.0.2 (including)
Openldap Openldap 1.0.3 (including) 1.0.3 (including)
Openldap Openldap 1.1 (including) 1.1 (including)
Openldap Openldap 1.1.1 (including) 1.1.1 (including)
Openldap Openldap 1.1.2 (including) 1.1.2 (including)
Openldap Openldap 1.1.3 (including) 1.1.3 (including)
Openldap Openldap 1.1.4 (including) 1.1.4 (including)
Openldap Openldap 1.2 (including) 1.2 (including)
Openldap Openldap 1.2.1 (including) 1.2.1 (including)
Openldap Openldap 1.2.2 (including) 1.2.2 (including)
Openldap Openldap 1.2.3 (including) 1.2.3 (including)
Openldap Openldap 1.2.4 (including) 1.2.4 (including)
Openldap Openldap 1.2.5 (including) 1.2.5 (including)
Openldap Openldap 1.2.6 (including) 1.2.6 (including)
Openldap Openldap 1.2.7 (including) 1.2.7 (including)
Openldap Openldap 1.2.8 (including) 1.2.8 (including)
Openldap Openldap 1.2.9 (including) 1.2.9 (including)
Openldap Openldap 1.2.10 (including) 1.2.10 (including)
Openldap Openldap 1.2.11 (including) 1.2.11 (including)
Openldap Openldap 1.2.12 (including) 1.2.12 (including)
Openldap Openldap 1.2.13 (including) 1.2.13 (including)
Openldap Openldap 2.0 (including) 2.0 (including)
Openldap Openldap 2.0.1 (including) 2.0.1 (including)
Openldap Openldap 2.0.2 (including) 2.0.2 (including)
Openldap Openldap 2.0.3 (including) 2.0.3 (including)
Openldap Openldap 2.0.4 (including) 2.0.4 (including)
Openldap Openldap 2.0.5 (including) 2.0.5 (including)
Openldap Openldap 2.0.6 (including) 2.0.6 (including)
Openldap Openldap 2.0.7 (including) 2.0.7 (including)
Openldap Openldap 2.0.8 (including) 2.0.8 (including)
Openldap Openldap 2.0.9 (including) 2.0.9 (including)
Openldap Openldap 2.0.10 (including) 2.0.10 (including)
Openldap Openldap 2.0.11 (including) 2.0.11 (including)
Openldap Openldap 2.0.11_9 (including) 2.0.11_9 (including)
Openldap Openldap 2.0.11_11 (including) 2.0.11_11 (including)
Openldap Openldap 2.0.11_11s (including) 2.0.11_11s (including)
Openldap Openldap 2.0.12 (including) 2.0.12 (including)
Openldap Openldap 2.0.13 (including) 2.0.13 (including)
Openldap Openldap 2.0.14 (including) 2.0.14 (including)
Openldap Openldap 2.0.15 (including) 2.0.15 (including)
Openldap Openldap 2.0.16 (including) 2.0.16 (including)
Openldap Openldap 2.0.17 (including) 2.0.17 (including)
Openldap Openldap 2.0.18 (including) 2.0.18 (including)
Openldap Openldap 2.0.19 (including) 2.0.19 (including)
Openldap Openldap 2.0.20 (including) 2.0.20 (including)
Openldap Openldap 2.0.21 (including) 2.0.21 (including)
Openldap Openldap 2.0.22 (including) 2.0.22 (including)
Openldap Openldap 2.0.23 (including) 2.0.23 (including)
Openldap Openldap 2.0.25 (including) 2.0.25 (including)
Openldap Openldap 2.0.27 (including) 2.0.27 (including)
Openldap Openldap 2.1.4 (including) 2.1.4 (including)
Openldap Openldap 2.1.10 (including) 2.1.10 (including)
Openldap Openldap 2.1.11 (including) 2.1.11 (including)
Openldap Openldap 2.1.12 (including) 2.1.12 (including)
Openldap Openldap 2.1.13 (including) 2.1.13 (including)
Openldap Openldap 2.1.14 (including) 2.1.14 (including)
Openldap Openldap 2.1.15 (including) 2.1.15 (including)
Openldap Openldap 2.1.16 (including) 2.1.16 (including)
Openldap Openldap 2.1.17 (including) 2.1.17 (including)
Openldap Openldap 2.1.18 (including) 2.1.18 (including)
Openldap Openldap 2.1.19 (including) 2.1.19 (including)
Openldap Openldap 2.1_.20 (including) 2.1_.20 (including)
Red Hat Enterprise Linux 3 RedHat nss_ldap-0:207-17 *
Red Hat Enterprise Linux 3 RedHat openldap-0:2.0.27-20 *

References