The LDAP name service (nsd) in IRIX 6.5.19 and earlier does not properly verify if the USERPASSWORD attribute has been provided by an LDAP server, which could allow attackers to log in without a password.
References
Link | Resource |
---|---|
ftp://patches.sgi.com/support/free/security/advisories/20030407-01-P | Patch Vendor Advisory |
http://www.securityfocus.com/bid/7442 | Patch Vendor Advisory |
http://www.ciac.org/ciac/bulletins/n-084.shtml | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/11860 |
Configurations
Configuration 1 (hide)
|
Information
Published : 2003-05-11 21:00
Updated : 2017-07-10 18:29
NVD link : CVE-2003-0174
Mitre link : CVE-2003-0174
JSON object : View
CWE
Products Affected
sgi
- irix