|
|
Log in / Subscribe / Register

cherokee: authentication bypass

Package(s):cherokee CVE #(s):CVE-2014-4668
Created:April 27, 2015 Updated:May 5, 2015
Description: From the CVE entry:

The cherokee_validator_ldap_check function in validator_ldap.c in Cherokee 1.2.103 and earlier, when LDAP is used, does not properly consider unauthenticated-bind semantics, which allows remote attackers to bypass authentication via an empty password.

Alerts:
Mandriva MDVSA-2015:225 cherokee 2015-05-04
Mageia MGASA-2015-0181 cherokee 2015-05-03
Fedora FEDORA-2015-6279 cherokee 2015-04-27
Fedora FEDORA-2015-6392 cherokee 2015-04-27

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds