HIGH · 7.5

CVE-2004-0823

OpenLDAP 1.0 through 2.1.19, as used in Apple Mac OS 10.3.4 and 10.3.5 and possibly other operating systems, may allow certain authentication schemes to use hashed (crypt) passwords in the userPasswor...

Vulnerability Description

OpenLDAP 1.0 through 2.1.19, as used in Apple Mac OS 10.3.4 and 10.3.5 and possibly other operating systems, may allow certain authentication schemes to use hashed (crypt) passwords in the userPassword attribute as if they were plaintext passwords, which allows remote attackers to re-use hashed passwords without decrypting them.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
OpenldapOpenldap1.0
AppleMac Os X10.2.8
AppleMac Os X Server10.2.8

References

FAQ

What is CVE-2004-0823?

CVE-2004-0823 is a vulnerability with a CVSS score of 7.5 (HIGH). OpenLDAP 1.0 through 2.1.19, as used in Apple Mac OS 10.3.4 and 10.3.5 and possibly other operating systems, may allow certain authentication schemes to use hashed (crypt) passwords in the userPasswor...

How severe is CVE-2004-0823?

CVE-2004-0823 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2004-0823?

Check the references section above for vendor advisories and patch information. Affected products include: Openldap Openldap, Apple Mac Os X, Apple Mac Os X Server.