CVE-2004-0823

OpenLDAP 1.0-2.1.19 - Remote Authentication Bypass via Hashed Password Reuse

Title source: llm
STIX 2.1

Description

OpenLDAP 1.0 through 2.1.19, as used in Apple Mac OS 10.3.4 and 10.3.5 and possibly other operating systems, may allow certain authentication schemes to use hashed (crypt) passwords in the userPassword attribute as if they were plaintext passwords, which allows remote attackers to re-use hashed passwords without decrypting them.

References (10)

Core 10
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/17300
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2005-751.html
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/12491/
Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/11137
Patch, Vendor Advisory third-party-advisory x_refsource_auscert
http://www.auscert.org.au/render.html?it=4363
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21520
Patch, Vendor Advisory vendor-advisory x_refsource_apple
http://www.securityfocus.com/advisories/7148
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/17233
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10703

Scores

EPSS 0.0274
EPSS Percentile 84.7%

Details

Status published
Products (50)
apple/mac_os_x 10.2.8
apple/mac_os_x 10.3.4
apple/mac_os_x 10.3.5
apple/mac_os_x_server 10.2.8
apple/mac_os_x_server 10.3.4
apple/mac_os_x_server 10.3.5
openldap/openldap 1.0
openldap/openldap 1.0.1
openldap/openldap 1.0.2
openldap/openldap 1.0.3
... and 40 more
Published Sep 07, 2004
Tracked Since Feb 18, 2026