Описание
Rule Set Based Access Control (RSBAC) before 1.3.5 does not properly use the Linux Kernel Crypto API for the Linux kernel 2.6.x, which allows context-dependent attackers to bypass authentication controls via unspecified vectors, possibly involving User Management password hashing and unchecked function return codes.
Rule Set Based Access Control (RSBAC) before 1.3.5 does not properly use the Linux Kernel Crypto API for the Linux kernel 2.6.x, which allows context-dependent attackers to bypass authentication controls via unspecified vectors, possibly involving User Management password hashing and unchecked function return codes.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2007-3945
- http://download.rsbac.org/code/1.3.5/changes-1.3.5.txt
- http://secunia.com/advisories/26147
- http://securityreason.com/securityalert/2911
- http://www.securityfocus.com/archive/1/474161/100/0/threaded
- http://www.securityfocus.com/bid/25001
- http://www.vupen.com/english/advisories/2007/2610
EPSS
CVE ID
Связанные уязвимости
Rule Set Based Access Control (RSBAC) before 1.3.5 does not properly use the Linux Kernel Crypto API for the Linux kernel 2.6.x, which allows context-dependent attackers to bypass authentication controls via unspecified vectors, possibly involving User Management password hashing and unchecked function return codes.
EPSS