PHPLDAPAdmin Unauthorized Access Vulnerability
BID:14694
Info
PHPLDAPAdmin Unauthorized Access Vulnerability
| Bugtraq ID: | 14694 |
| Class: | Access Validation Error |
| CVE: |
CVE-2005-2654 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 30 2005 12:00AM |
| Updated: | Jul 12 2009 05:06PM |
| Credit: | Discovered by Alexander Gerasiov. |
| Vulnerable: |
phpldapadmin phpldapadmin 0.9.5 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 Gentoo Linux |
| Not Vulnerable: | |
Discussion
PHPLDAPAdmin Unauthorized Access Vulnerability
phpldapadmin is prone to an unauthorized access vulnerability. This issue is due to a failure in the application to properly validate user credentials before granting access to LDAP administrative functions.
An attacker can exploit this vulnerability to login to the server anonymously, and utilize administrative functions to modify the LDAP database.
phpldapadmin is prone to an unauthorized access vulnerability. This issue is due to a failure in the application to properly validate user credentials before granting access to LDAP administrative functions.
An attacker can exploit this vulnerability to login to the server anonymously, and utilize administrative functions to modify the LDAP database.
Exploit / POC
PHPLDAPAdmin Unauthorized Access Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
PHPLDAPAdmin Unauthorized Access Vulnerability
Solution:
Debian Linux has released security advisory DSA 790-1 addressing this issue. Please see the referenced advisory for details on obtaining and applying the appropriate updates.
Gentoo has released advisory GLSA 200509-04 and fixes to address this issue. To obtain fixes, execute the following:
emerge --sync
emerge --ask --oneshot --verbose ">=net-nds/phpldapadmin-0.9.7_alpha6"
Mandriva Linux has released security advisory MDKSA-2005:212 addressing this issue. Please see the referenced advisory for details on obtaining and applying the appropriate updates.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
phpldapadmin phpldapadmin 0.9.5
Solution:
Debian Linux has released security advisory DSA 790-1 addressing this issue. Please see the referenced advisory for details on obtaining and applying the appropriate updates.
Gentoo has released advisory GLSA 200509-04 and fixes to address this issue. To obtain fixes, execute the following:
emerge --sync
emerge --ask --oneshot --verbose ">=net-nds/phpldapadmin-0.9.7_alpha6"
Mandriva Linux has released security advisory MDKSA-2005:212 addressing this issue. Please see the referenced advisory for details on obtaining and applying the appropriate updates.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
phpldapadmin phpldapadmin 0.9.5
-
Debian phpldapadmin_0.9.5-3sarge2_all.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/p/phpldapadmin/phpldapadm in_0.9.5-3sarge2_all.deb