|
|
Subscribe / Log in / New account

libuser: default user password

Package(s):libuser CVE #(s):CVE-2011-0002
Created:January 20, 2011 Updated:April 21, 2011
Description:

From the Red Hat advisory:

It was discovered that libuser did not set the password entry correctly when creating LDAP (Lightweight Directory Access Protocol) users. If an administrator did not assign a password to an LDAP based user account, either at account creation with luseradd, or with lpasswd after account creation, an attacker could use this flaw to log into that account with a default password string that should have been rejected. (CVE-2011-0002)

Alerts:
CentOS CESA-2011:0170 libuser 2011-02-04
Mandriva MDVSA-2011:019 libuser 2011-01-26
Fedora FEDORA-2011-0320 libuser 2011-01-12
Fedora FEDORA-2011-0316 libuser 2011-01-12
Red Hat RHSA-2011:0170-01 libuser 2011-01-20
CentOS CESA-2011:0170 libuser 2011-04-20

to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds