Cryptographic Issues Affecting libuser package, versions <0:0.56.13-4.el6_0.1
Threat Intelligence
EPSS
0.75% (82nd
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-CENTOS6-LIBUSER-2038308
- published 26 Jul 2021
- disclosed 10 Jan 2011
Introduced: 10 Jan 2011
CVE-2011-0002 Open this link in a new tabHow to fix?
Upgrade Centos:6
libuser
to version 0:0.56.13-4.el6_0.1 or higher.
NVD Description
Note: Versions mentioned in the description apply only to the upstream libuser
package and not the libuser
package as distributed by Centos
.
See How to fix?
for Centos:6
relevant fixed versions and status.
libuser before 0.57 uses a cleartext password value of (1) !! or (2) x for new LDAP user accounts, which makes it easier for remote attackers to obtain access by specifying one of these values.
References
- http://www.securityfocus.com/bid/45791
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705
- https://bugzilla.redhat.com/show_bug.cgi?id=643227
- https://fedorahosted.org/libuser/browser/NEWS?rev=libuser-0.57
- https://access.redhat.com/security/cve/CVE-2011-0002
- http://lists.fedoraproject.org/pipermail/package-announce/2011-January/053365.html
- http://lists.fedoraproject.org/pipermail/package-announce/2011-January/053378.html
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:019
- http://www.osvdb.org/70421
- http://www.redhat.com/support/errata/RHSA-2011-0170.html
- https://access.redhat.com/errata/RHSA-2011:0170
- http://securitytracker.com/id?1024960
- http://secunia.com/advisories/42891
- http://secunia.com/advisories/42966
- http://secunia.com/advisories/43047
- http://www.vupen.com/english/advisories/2011/0184
- http://www.vupen.com/english/advisories/2011/0201
- http://www.vupen.com/english/advisories/2011/0226
- https://exchange.xforce.ibmcloud.com/vulnerabilities/64677
CVSS Scores
version 3.1