LWN.net Logo

libuser: default user password

Package(s):libuser CVE #(s):CVE-2011-0002
Created:January 20, 2011 Updated:April 21, 2011
Description:

From the Red Hat advisory:

It was discovered that libuser did not set the password entry correctly when creating LDAP (Lightweight Directory Access Protocol) users. If an administrator did not assign a password to an LDAP based user account, either at account creation with luseradd, or with lpasswd after account creation, an attacker could use this flaw to log into that account with a default password string that should have been rejected. (CVE-2011-0002)

Alerts:
CentOS CESA-2011:0170 2011-02-04
Mandriva MDVSA-2011:019 2011-01-26
Fedora FEDORA-2011-0320 2011-01-12
Fedora FEDORA-2011-0316 2011-01-12
Red Hat RHSA-2011:0170-01 2011-01-20
CentOS CESA-2011:0170 2011-04-20

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds