SGI IRIX Name Service Daemon LDAP UserPassword Bypass Vulnerability
BID:7442
Info
SGI IRIX Name Service Daemon LDAP UserPassword Bypass Vulnerability
| Bugtraq ID: | 7442 |
| Class: | Design Error |
| CVE: |
CVE-2003-0174 |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 25 2003 12:00AM |
| Updated: | Jul 11 2009 09:07PM |
| Credit: | Vulnerability announced by SGI. |
| Vulnerable: |
SGI IRIX 6.5.19 m SGI IRIX 6.5.19 f SGI IRIX 6.5.19 SGI IRIX 6.5.18 m SGI IRIX 6.5.18 f SGI IRIX 6.5.18 SGI IRIX 6.5.17 m SGI IRIX 6.5.17 f SGI IRIX 6.5.17 SGI IRIX 6.5.16 m SGI IRIX 6.5.16 f SGI IRIX 6.5.16 SGI IRIX 6.5.15 m SGI IRIX 6.5.15 f SGI IRIX 6.5.15 SGI IRIX 6.5.14 m SGI IRIX 6.5.14 f SGI IRIX 6.5.14 SGI IRIX 6.5.13 m SGI IRIX 6.5.13 f SGI IRIX 6.5.13 SGI IRIX 6.5.12 m SGI IRIX 6.5.12 f SGI IRIX 6.5.12 SGI IRIX 6.5.11 m SGI IRIX 6.5.11 f SGI IRIX 6.5.11 SGI IRIX 6.5.10 m SGI IRIX 6.5.10 f SGI IRIX 6.5.10 SGI IRIX 6.5.9 m SGI IRIX 6.5.9 f SGI IRIX 6.5.9 SGI IRIX 6.5.8 m SGI IRIX 6.5.8 f SGI IRIX 6.5.8 SGI IRIX 6.5.7 m SGI IRIX 6.5.7 f SGI IRIX 6.5.7 SGI IRIX 6.5.6 m SGI IRIX 6.5.6 f SGI IRIX 6.5.6 SGI IRIX 6.5.5 m SGI IRIX 6.5.5 f SGI IRIX 6.5.5 SGI IRIX 6.5.4 m SGI IRIX 6.5.4 f SGI IRIX 6.5.4 SGI IRIX 6.5.3 m SGI IRIX 6.5.3 f SGI IRIX 6.5.3 SGI IRIX 6.5.2 m SGI IRIX 6.5.2 f SGI IRIX 6.5.2 SGI IRIX 6.5.1 SGI IRIX 6.5 |
| Not Vulnerable: | |
Discussion
SGI IRIX Name Service Daemon LDAP UserPassword Bypass Vulnerability
It has been reported that the SGI IRIX implementation of LDAP does not properly handle some attributes from LDAP servers. Because of this, it may be possible for a remote user to gain unauthorized access to a target server.
It has been reported that the SGI IRIX implementation of LDAP does not properly handle some attributes from LDAP servers. Because of this, it may be possible for a remote user to gain unauthorized access to a target server.
Exploit / POC
SGI IRIX Name Service Daemon LDAP UserPassword Bypass Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
SGI IRIX Name Service Daemon LDAP UserPassword Bypass Vulnerability
Solution:
SGI has release fixes to address this issue. Additionally, SGI has stated that this issue will be resolved in the forthcoming 6.5.20 release.
SGI IRIX 6.5.15 m
SGI IRIX 6.5.15
SGI IRIX 6.5.15 f
SGI IRIX 6.5.16 m
SGI IRIX 6.5.16 f
SGI IRIX 6.5.16
SGI IRIX 6.5.17 f
SGI IRIX 6.5.17
SGI IRIX 6.5.17 m
SGI IRIX 6.5.18 m
SGI IRIX 6.5.18
SGI IRIX 6.5.18 f
SGI IRIX 6.5.19
SGI IRIX 6.5.19 m
SGI IRIX 6.5.19 f
Solution:
SGI has release fixes to address this issue. Additionally, SGI has stated that this issue will be resolved in the forthcoming 6.5.20 release.
SGI IRIX 6.5.15 m
SGI IRIX 6.5.15
SGI IRIX 6.5.15 f
SGI IRIX 6.5.16 m
SGI IRIX 6.5.16 f
SGI IRIX 6.5.16
SGI IRIX 6.5.17 f
SGI IRIX 6.5.17
SGI IRIX 6.5.17 m
SGI IRIX 6.5.18 m
SGI IRIX 6.5.18
SGI IRIX 6.5.18 f
SGI IRIX 6.5.19
SGI IRIX 6.5.19 m
SGI IRIX 6.5.19 f