Description
libuser before 0.57 uses a cleartext password value of (1) !! or (2) x for new LDAP user accounts, which makes it easier for remote attackers to obtain access by specifying one of these values.
CVSS vector
AV:N/AC:L/C:P/I:P/A:NExploitability: 10.0 | Impact: 4.9Complexity: Low
Availability: None
Affected Packages3 packages
🔴Vulnerability Details
2GHSAGHSA-6ppq-r3vw-8xm4: libuser before 0↗2022-05-03 ▶ OSVCVE-2011-0002: libuser before 0↗2011-01-22 ▶ 💥Exploits & PoCs
1Exploit-DBMicrosoft Terminal Services - Use-After-Free (MS12-020)↗2012-03-16 ▶ 📋Vendor Advisories
2Red Hatlibuser creates LDAP users with a default password↗2011-01-10 ▶ DebianCVE-2011-0002: libuser - libuser before 0.57 uses a cleartext password value of (1) !! or (2) x for new L...↗2011 ▶ 💬Community
2BugzillaCVE-2011-0002 libuser creates LDAP users with a default password [fedora-all]↗2011-01-10 ▶ BugzillaCVE-2011-0002 libuser creates LDAP users with a default password↗2010-10-15 ▶