The LDAP name service (nsd) in IRIX 6.5.19 and earlier does not properly verify if the USERPASSWORD attribute has been provided by an LDAP server, which could allow attackers to log in without a password.
References
Link | Resource |
---|---|
ftp://patches.sgi.com/support/free/security/advisories/20030407-01-P | Broken Link Patch Vendor Advisory |
http://www.ciac.org/ciac/bulletins/n-084.shtml | Broken Link |
http://www.securityfocus.com/bid/7442 | Broken Link Patch Third Party Advisory VDB Entry Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/11860 | Third Party Advisory VDB Entry |
Configurations
History
No history.
Information
Published : 2003-05-12 04:00
Updated : 2024-02-08 20:45
NVD link : CVE-2003-0174
Mitre link : CVE-2003-0174
CVE.ORG link : CVE-2003-0174
JSON object : View
Products Affected
sgi
- irix
CWE
CWE-346
Origin Validation Error