Svi
Pretraži prema proizvođaču
Pretraži prema CWE oznaci
O usluzi
Pretplate
Jezik
hr
en
CVE-2008-3274 - CERT CVE
CVE-2008-3274
ID
CVE-2008-3274
Sažetak
The default configuration of Red Hat Enterprise IPA 1.0.0 and FreeIPA before 1.1.1 places ldap:///anyone on the read ACL for the krbMKey attribute, which allows remote attackers to obtain the Kerberos master key via an anonymous LDAP query.
Reference
http://www.freeipa.org/page/News
http://www.securityfocus.com/bid/31111
https://bugzilla.redhat.com/show_bug.cgi?id=457835
http://rhn.redhat.com/errata/RHSA-2008-0860.html
http://www.freeipa.org/page/Downloads
http://www.freeipa.org/page/CVE-2008-3274
http://secunia.com/advisories/31861
https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00733.html
https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00743.html
http://www.securitytracker.com/id?1020850
http://git.fedorahosted.org/git/freeipa.git/?p=freeipa.git%3Ba=commit%3Bh=9932887f2af38b9701efec27707648c026ec445c
CVSS
Base:
5.0
Impact:
2.9
Exploitability:
10.0
Pristup
Vektor
Složenost
Autentikacija
NETWORK
LOW
NONE
Impact
Povjerljivost
Cjelovitost
Dostupnost
PARTIAL
NONE
NONE
CVSS vektor
AV:N/AC:L/Au:N/C:P/I:N/A:N
Zadnje važnije ažuriranje
13-02-2023 - 02:19
Objavljeno
12-09-2008 - 16:56