Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-4668

Опубликовано: 02 июл. 2014
Источник: ubuntu
Приоритет: medium
CVSS2: 6.8

Описание

The cherokee_validator_ldap_check function in validator_ldap.c in Cherokee 1.2.103 and earlier, when LDAP is used, does not properly consider unauthenticated-bind semantics, which allows remote attackers to bypass authentication via an empty password.

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

DNE

lucid

ignored

end of life
precise

ignored

end of life
precise/esm

DNE

precise was needed
saucy

DNE

trusty

DNE

trusty/esm

DNE

upstream

needed

utopic

DNE

Показывать по

6.8 Medium

CVSS2

Связанные уязвимости

nvd
больше 11 лет назад

The cherokee_validator_ldap_check function in validator_ldap.c in Cherokee 1.2.103 and earlier, when LDAP is used, does not properly consider unauthenticated-bind semantics, which allows remote attackers to bypass authentication via an empty password.

debian
больше 11 лет назад

The cherokee_validator_ldap_check function in validator_ldap.c in Cher ...

github
больше 3 лет назад

The cherokee_validator_ldap_check function in validator_ldap.c in Cherokee 1.2.103 and earlier, when LDAP is used, does not properly consider unauthenticated-bind semantics, which allows remote attackers to bypass authentication via an empty password.

6.8 Medium

CVSS2