Debian Horde Default Administrator Password Vulnerability
BID:15337
CVE-2005-3344 |Info
Debian Horde Default Administrator Password Vulnerability
| Bugtraq ID: | 15337 |
| Class: | Design Error |
| CVE: |
CVE-2005-3344 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 07 2005 12:00AM |
| Updated: | Nov 07 2005 12:00AM |
| Credit: | Mike O'Connor is credited with the discovery of this vulnerability. This issue was announced in the referenced Debian advisory. |
| Vulnerable: |
Debian horde 3.0.4 |
| Not Vulnerable: | |
Discussion
Debian Horde Default Administrator Password Vulnerability
The default Horde3 installation for Debian has a blank administrator password.
A local or remote attacker can exploit this vulnerability to gain administrative access to the affected application. This may aid an attacker in further attacks against the underlying system; other attacks are also possible.
This issue is specific to Debian Linux installations of the Horde3 application.
The default Horde3 installation for Debian has a blank administrator password.
A local or remote attacker can exploit this vulnerability to gain administrative access to the affected application. This may aid an attacker in further attacks against the underlying system; other attacks are also possible.
This issue is specific to Debian Linux installations of the Horde3 application.
Exploit / POC
Debian Horde Default Administrator Password Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Debian Horde Default Administrator Password Vulnerability
Solution:
Debian Linux has released security advisory DSA 884-1 with fixes addressing this issue. Please see the referenced advisory for further information.
Debian horde 3.0.4
Solution:
Debian Linux has released security advisory DSA 884-1 with fixes addressing this issue. Please see the referenced advisory for further information.
Debian horde 3.0.4
-
Debian horde3_3.0.4-4sarge1_all.deb
http://security.debian.org/pool/updates/main/h/horde3/horde3_3.0.4-4sa rge1_all.deb
References
Debian Horde Default Administrator Password Vulnerability
References:
References:
- Pandora Homepage (Pandora FMS Team)