Kolab Groupware Server OpenLDAP Plaintext Password Storage Vulnerability
BID:10277
Info
Kolab Groupware Server OpenLDAP Plaintext Password Storage Vulnerability
| Bugtraq ID: | 10277 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | May 05 2004 12:00AM |
| Updated: | May 05 2004 12:00AM |
| Credit: | Discovery is credited to Luca Villani <[email protected]>. |
| Vulnerable: |
OpenPKG OpenPKG 2.0 Kolab Kolab Groupware Server 1.0.8 Kolab Kolab Groupware Server 1.0.7 Kolab Kolab Groupware Server 1.0.6 Kolab Kolab Groupware Server 1.0.5 Kolab Kolab Groupware Server 1.0.3 Kolab Kolab Groupware Server 1.0.1 Kolab Kolab Groupware Server 1.0 |
| Not Vulnerable: |
Kolab Kolab Groupware Server 1.0 -20040426 |
Discussion
Kolab Groupware Server OpenLDAP Plaintext Password Storage Vulnerability
It has been reported that Kolab groupware server is prone to a plaintext password storage vulnerability that may allow an attacker to disclose OpenLDAP passwords that are stored in plaintext format.
Kolab Server versions 1.0.8 and prior may be prone to this issue.
It has been reported that Kolab groupware server is prone to a plaintext password storage vulnerability that may allow an attacker to disclose OpenLDAP passwords that are stored in plaintext format.
Kolab Server versions 1.0.8 and prior may be prone to this issue.
Exploit / POC
Kolab Groupware Server OpenLDAP Plaintext Password Storage Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Kolab Groupware Server OpenLDAP Plaintext Password Storage Vulnerability
Solution:
Mandrake has released a security advisory (MDKSA-2004:052) and updates to address this issue in Mandrake Linux 10. Users are advised to see the referenced advisory for further details regarding obtaining and applying fixes.
OpenPKG has released an advisory OpenPKG-SA-2004.019 to address this issue. Please see the referenced advisory for more information.
The vendor has fixed this issue in Kolab 1.0-20040426:
Kolab Kolab Groupware Server 1.0
Kolab Kolab Groupware Server 1.0.1
Kolab Kolab Groupware Server 1.0.3
Kolab Kolab Groupware Server 1.0.5
Kolab Kolab Groupware Server 1.0.6
Kolab Kolab Groupware Server 1.0.7
Kolab Kolab Groupware Server 1.0.8
OpenPKG OpenPKG 2.0
Solution:
Mandrake has released a security advisory (MDKSA-2004:052) and updates to address this issue in Mandrake Linux 10. Users are advised to see the referenced advisory for further details regarding obtaining and applying fixes.
OpenPKG has released an advisory OpenPKG-SA-2004.019 to address this issue. Please see the referenced advisory for more information.
The vendor has fixed this issue in Kolab 1.0-20040426:
Kolab Kolab Groupware Server 1.0
-
Kolab kolab-1.0-20040426
http://www.erfrakon.de/projects/kolab/download/ -
Mandrake kolab-server-1.0-0.23.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kolab-server-1.0-0.23.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php
Kolab Kolab Groupware Server 1.0.1
-
Kolab kolab-1.0-20040426
http://www.erfrakon.de/projects/kolab/download/
Kolab Kolab Groupware Server 1.0.3
-
Kolab kolab-1.0-20040426
http://www.erfrakon.de/projects/kolab/download/
Kolab Kolab Groupware Server 1.0.5
-
Kolab kolab-1.0-20040426
http://www.erfrakon.de/projects/kolab/download/
Kolab Kolab Groupware Server 1.0.6
-
Kolab kolab-1.0-20040426
http://www.erfrakon.de/projects/kolab/download/
Kolab Kolab Groupware Server 1.0.7
-
Kolab kolab-1.0-20040426
http://www.erfrakon.de/projects/kolab/download/
Kolab Kolab Groupware Server 1.0.8
-
Kolab kolab-1.0-20040426
http://www.erfrakon.de/projects/kolab/download/
OpenPKG OpenPKG 2.0
-
OpenPKG kolab-20040217-2.0.2.src.rpm
ftp://ftp.openpkg.org/release/2.0/UPD/kolab-20040217-2.0.2.src.rpm
References
Kolab Groupware Server OpenLDAP Plaintext Password Storage Vulnerability
References:
References: