CVE-2004-0823
OpenLDAP 1.0-2.1.19 - Remote Authentication Bypass via Hashed Password Reuse
Title source: llmDescription
OpenLDAP 1.0 through 2.1.19, as used in Apple Mac OS 10.3.4 and 10.3.5 and possibly other operating systems, may allow certain authentication schemes to use hashed (crypt) passwords in the userPassword attribute as if they were plaintext passwords, which allows remote attackers to re-use hashed passwords without decrypting them.
References (10)
Core 10
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/17300
Vendor Advisory x_refsource_confirm
http://support.avaya.com/elmodocs2/security/ASA-2006-157.htm
Vendor Advisory vendor-advisory
x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2005-751.html
Patch, Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/12491/
Patch, Vendor Advisory vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/11137
Patch, Vendor Advisory third-party-advisory
x_refsource_auscert
http://www.auscert.org.au/render.html?it=4363
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/21520
Patch, Vendor Advisory vendor-advisory
x_refsource_apple
http://www.securityfocus.com/advisories/7148
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/17233
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10703
Scores
EPSS
0.0274
EPSS Percentile
84.7%
Details
Status
published
Products (50)
apple/mac_os_x
10.2.8
apple/mac_os_x
10.3.4
apple/mac_os_x
10.3.5
apple/mac_os_x_server
10.2.8
apple/mac_os_x_server
10.3.4
apple/mac_os_x_server
10.3.5
openldap/openldap
1.0
openldap/openldap
1.0.1
openldap/openldap
1.0.2
openldap/openldap
1.0.3
... and 40 more
Published
Sep 07, 2004
Tracked Since
Feb 18, 2026