CVE-2004-0823
Summary
| CVE | CVE-2004-0823 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2004-09-07 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | OpenLDAP 1.0 through 2.1.19, as used in Apple Mac OS 10.3.4 and 10.3.5 and possibly other operating systems, may allow certain authentication schemes to use hashed (crypt) passwords in the userPassword attribute as if they were plaintext passwords, which allows remote attackers to re-use hashed passwords without decrypting them. |
Risk And Classification
Primary CVSS: v2.0 7.5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Apple | Mac Os X | 10.2.8 | All | All | All |
| Operating System | Apple | Mac Os X | 10.3.4 | All | All | All |
| Operating System | Apple | Mac Os X | 10.3.5 | All | All | All |
| Operating System | Apple | Mac Os X Server | 10.2.8 | All | All | All |
| Operating System | Apple | Mac Os X Server | 10.3.4 | All | All | All |
| Operating System | Apple | Mac Os X Server | 10.3.5 | All | All | All |
| Application | Openldap | Openldap | 1.0 | All | All | All |
| Application | Openldap | Openldap | 1.0.1 | All | All | All |
| Application | Openldap | Openldap | 1.0.2 | All | All | All |
| Application | Openldap | Openldap | 1.0.3 | All | All | All |
| Application | Openldap | Openldap | 1.1 | All | All | All |
| Application | Openldap | Openldap | 1.1.1 | All | All | All |
| Application | Openldap | Openldap | 1.1.2 | All | All | All |
| Application | Openldap | Openldap | 1.1.3 | All | All | All |
| Application | Openldap | Openldap | 1.1.4 | All | All | All |
| Application | Openldap | Openldap | 1.2 | All | All | All |
| Application | Openldap | Openldap | 1.2.1 | All | All | All |
| Application | Openldap | Openldap | 1.2.10 | All | All | All |
| Application | Openldap | Openldap | 1.2.11 | All | All | All |
| Application | Openldap | Openldap | 1.2.12 | All | All | All |
| Application | Openldap | Openldap | 1.2.13 | All | All | All |
| Application | Openldap | Openldap | 1.2.2 | All | All | All |
| Application | Openldap | Openldap | 1.2.3 | All | All | All |
| Application | Openldap | Openldap | 1.2.4 | All | All | All |
| Application | Openldap | Openldap | 1.2.5 | All | All | All |
| Application | Openldap | Openldap | 1.2.6 | All | All | All |
| Application | Openldap | Openldap | 1.2.7 | All | All | All |
| Application | Openldap | Openldap | 1.2.8 | All | All | All |
| Application | Openldap | Openldap | 1.2.9 | All | All | All |
| Application | Openldap | Openldap | 2.0 | All | All | All |
| Application | Openldap | Openldap | 2.0.1 | All | All | All |
| Application | Openldap | Openldap | 2.0.10 | All | All | All |
| Application | Openldap | Openldap | 2.0.11 | All | All | All |
| Application | Openldap | Openldap | 2.0.11_11 | All | All | All |
| Application | Openldap | Openldap | 2.0.11_11s | All | All | All |
| Application | Openldap | Openldap | 2.0.11_9 | All | All | All |
| Application | Openldap | Openldap | 2.0.12 | All | All | All |
| Application | Openldap | Openldap | 2.0.13 | All | All | All |
| Application | Openldap | Openldap | 2.0.14 | All | All | All |
| Application | Openldap | Openldap | 2.0.15 | All | All | All |
| Application | Openldap | Openldap | 2.0.16 | All | All | All |
| Application | Openldap | Openldap | 2.0.17 | All | All | All |
| Application | Openldap | Openldap | 2.0.18 | All | All | All |
| Application | Openldap | Openldap | 2.0.19 | All | All | All |
| Application | Openldap | Openldap | 2.0.2 | All | All | All |
| Application | Openldap | Openldap | 2.0.20 | All | All | All |
| Application | Openldap | Openldap | 2.0.21 | All | All | All |
| Application | Openldap | Openldap | 2.0.22 | All | All | All |
| Application | Openldap | Openldap | 2.0.23 | All | All | All |
| Application | Openldap | Openldap | 2.0.25 | All | All | All |
| Application | Openldap | Openldap | 2.0.27 | All | All | All |
| Application | Openldap | Openldap | 2.0.3 | All | All | All |
| Application | Openldap | Openldap | 2.0.4 | All | All | All |
| Application | Openldap | Openldap | 2.0.5 | All | All | All |
| Application | Openldap | Openldap | 2.0.6 | All | All | All |
| Application | Openldap | Openldap | 2.0.7 | All | All | All |
| Application | Openldap | Openldap | 2.0.8 | All | All | All |
| Application | Openldap | Openldap | 2.0.9 | All | All | All |
| Application | Openldap | Openldap | 2.1.10 | All | All | All |
| Application | Openldap | Openldap | 2.1.11 | All | All | All |
| Application | Openldap | Openldap | 2.1.12 | All | All | All |
| Application | Openldap | Openldap | 2.1.13 | All | All | All |
| Application | Openldap | Openldap | 2.1.14 | All | All | All |
| Application | Openldap | Openldap | 2.1.15 | All | All | All |
| Application | Openldap | Openldap | 2.1.16 | All | All | All |
| Application | Openldap | Openldap | 2.1.17 | All | All | All |
| Application | Openldap | Openldap | 2.1.18 | All | All | All |
| Application | Openldap | Openldap | 2.1.19 | All | All | All |
| Application | Openldap | Openldap | 2.1.4 | All | All | All |
| Application | Openldap | Openldap | 2.1_.20 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Secunia - Advisories - Red Hat update for openldap / nss_ldap | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| ASA-2006-157 (RHSA-2005-751) | af854a3a-2127-422b-91ae-364da2661108 | support.avaya.com | |
| Advisory: Security Update 2004-09-07 | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch, Vendor Advisory |
| Avaya Products Multiple Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Secunia - Advisories - Mac OS X Security Update Fixes Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Patch, Vendor Advisory |
| OpenLDAP Ambiguous Password Attribute Weakness | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch, Vendor Advisory |
| AusCERT - ESB-2004.0559 -- APPLE-SA-0024-09-07 -- Security Update 2003-09-07 | af854a3a-2127-422b-91ae-364da2661108 | www.auscert.org.au | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.