RSBAC User Management Crypto API Authentication Bypass Vulnerability
BID:25001
Info
RSBAC User Management Crypto API Authentication Bypass Vulnerability
| Bugtraq ID: | 25001 |
| Class: | Access Validation Error |
| CVE: |
CVE-2007-3945 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 23 2007 12:00AM |
| Updated: | May 07 2015 05:36PM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
RSBAC RSBAC 1.3.4 RSBAC RSBAC 1.3.3 |
| Not Vulnerable: |
RSBAC RSBAC 1.3.5 |
Discussion
RSBAC User Management Crypto API Authentication Bypass Vulnerability
RSBAC (Rule Set Based Access Control) is prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to gain unauthorized access to an affected system.
This issue affects RSBAC 1.3.3 and 1.3.4 running on Linux Kernel 2.6.20 and prior versions.
RSBAC (Rule Set Based Access Control) is prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to gain unauthorized access to an affected system.
This issue affects RSBAC 1.3.3 and 1.3.4 running on Linux Kernel 2.6.20 and prior versions.
Exploit / POC
RSBAC User Management Crypto API Authentication Bypass Vulnerability
An attacker can exploit this issue through normal login mechanisms.
An attacker can exploit this issue through normal login mechanisms.
Solution / Fix
RSBAC User Management Crypto API Authentication Bypass Vulnerability
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Solution:
The vendor released an update to address this issue. Please see the references for more information.
References
RSBAC User Management Crypto API Authentication Bypass Vulnerability
References:
References: