Fedora SSSD BE Database No Password Authentication Bypass Vulnerability
BID:35868
Info
Fedora SSSD BE Database No Password Authentication Bypass Vulnerability
| Bugtraq ID: | 35868 |
| Class: | Design Error |
| CVE: |
CVE-2009-2410 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 29 2009 12:00AM |
| Updated: | Apr 13 2015 09:43PM |
| Credit: | Jenny Galipeau |
| Vulnerable: |
Redhat SSSD 0.4.1-2 |
| Not Vulnerable: |
Redhat SSSD 0.4.1-3 |
Discussion
Fedora SSSD BE Database No Password Authentication Bypass Vulnerability
Fedora SSSD is prone to an authentication-bypass vulnerability.
Attackers can exploit this issue to gain unauthorized access to affected computers. Successfully exploiting this issue may lead to other attacks.
Fedora SSSD is prone to an authentication-bypass vulnerability.
Attackers can exploit this issue to gain unauthorized access to affected computers. Successfully exploiting this issue may lead to other attacks.
Exploit / POC
Fedora SSSD BE Database No Password Authentication Bypass Vulnerability
Attackers can use readily available tools to exploit this issue.
Attackers can use readily available tools to exploit this issue.
Solution / Fix
Fedora SSSD BE Database No Password Authentication Bypass Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Fedora SSSD BE Database No Password Authentication Bypass Vulnerability
References:
References:
- (CVE-2009-2410) CVE-2009-2410 If internal sssd user has no password set, the use (Jenny Galipeau)
- SSSD Homepage (Fedora)