The (1) Zend_Ldap class in Zend before 1.12.9 and (2) ZendLdap component in Zend 2.x before 2.2.8 and 2.3.x before 2.3.3 allows remote attackers to bypass authentication via a password starting with a null byte, which triggers an unauthenticated bind.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Zend_framework | Zend | * | 1.12.7 (including) |
Zend_framework | Zend | 1.12.0 (including) | 1.12.0 (including) |
Zend_framework | Zend | 1.12.0-rc1 (including) | 1.12.0-rc1 (including) |
Zend_framework | Zend | 1.12.0-rc2 (including) | 1.12.0-rc2 (including) |
Zend_framework | Zend | 1.12.0-rc3 (including) | 1.12.0-rc3 (including) |
Zend_framework | Zend | 1.12.0-rc4 (including) | 1.12.0-rc4 (including) |
Zend_framework | Zend | 1.12.1 (including) | 1.12.1 (including) |
Zend_framework | Zend | 1.12.2 (including) | 1.12.2 (including) |
Zend_framework | Zend | 1.12.3 (including) | 1.12.3 (including) |
Zend_framework | Zend | 1.12.5 (including) | 1.12.5 (including) |
Zend_framework | Zend | 2.0.0 (including) | 2.0.0 (including) |
Zend_framework | Zend | 2.01 (including) | 2.01 (including) |
Zend_framework | Zend | 2.2.2 (including) | 2.2.2 (including) |
Zend_framework | Zend | 2.2.3 (including) | 2.2.3 (including) |
Zend_framework | Zend | 2.2.4 (including) | 2.2.4 (including) |
Zend_framework | Zend | 2.2.5 (including) | 2.2.5 (including) |
Zend_framework | Zend | 2.2.6 (including) | 2.2.6 (including) |
Zend_framework | Zend | 2.2.7 (including) | 2.2.7 (including) |
Zend_framework | Zend | 2.3.0 (including) | 2.3.0 (including) |
Zend_framework | Zend | 2.3.1 (including) | 2.3.1 (including) |
Zend_framework | Zend | 2.3.2 (including) | 2.3.2 (including) |
Zend-framework | Ubuntu | esm-apps/xenial | * |
Zend-framework | Ubuntu | lucid | * |
Zend-framework | Ubuntu | precise | * |
Zend-framework | Ubuntu | trusty | * |
Zend-framework | Ubuntu | utopic | * |
Zend-framework | Ubuntu | vivid | * |
Zend-framework | Ubuntu | wily | * |
Zend-framework | Ubuntu | xenial | * |
Zend-framework | Ubuntu | yakkety | * |
Zendframework | Ubuntu | lucid | * |
Zendframework | Ubuntu | upstream | * |