The authenticate function in LDAPUserFolder/LDAPUserFolder.py in zope-ldapuserfolder 2.9-1 does not verify the password for the emergency account, which allows remote attackers to gain privileges.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Zope-ldapuserfolder | Jens_vagelpohl | 2.9-1 (including) | 2.9-1 (including) |
Zope-ldapuserfolder | Ubuntu | hardy | * |
Zope-ldapuserfolder | Ubuntu | jaunty | * |
Zope-ldapuserfolder | Ubuntu | karmic | * |
Zope-ldapuserfolder | Ubuntu | upstream | * |