Zope PluggableAuthService 'updateUser()' Method Denial Of Service Vulnerability
BID:48053
Info
Zope PluggableAuthService 'updateUser()' Method Denial Of Service Vulnerability
| Bugtraq ID: | 48053 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 30 2011 12:00AM |
| Updated: | May 30 2011 12:00AM |
| Credit: | Alan Hoey |
| Vulnerable: |
Zope Zope 2.11.8 Zope PluggableAuthService 1.7 Zope PluggableAuthService 1.6 Zope PluggableAuthService 1.5 |
| Not Vulnerable: |
Zope PluggableAuthService 1.7.5 Zope PluggableAuthService 1.6.5 Zope PluggableAuthService 1.5.5 |
Discussion
Zope PluggableAuthService 'updateUser()' Method Denial Of Service Vulnerability
Zope PluggableAuthService is prone to a denial-of-service vulnerability.
An authenticated attacker can exploit this issue to reset their username to an existing username, resulting in a persistent denial-of-service condition for the victim user.
Versions prior to Zope PluggableAuthService 1.5.5, 1.6.5, and 1.7.5 are vulnerable.
Zope PluggableAuthService is prone to a denial-of-service vulnerability.
An authenticated attacker can exploit this issue to reset their username to an existing username, resulting in a persistent denial-of-service condition for the victim user.
Versions prior to Zope PluggableAuthService 1.5.5, 1.6.5, and 1.7.5 are vulnerable.
References
Zope PluggableAuthService 'updateUser()' Method Denial Of Service Vulnerability
References:
References:
- [Zope-Annce] PAS 1.5.5, 1.6.5, and 1.7.5 released (Tres Seaver)
- manage_updatePasswordForm allows DoS against other users (Tres Seaver)
- PluggableAuthService Homepage (Zope)
- Zope Homepage (Zope)