SurgeLDAP Insecure Password Storage Vulnerability
BID:8409
Info
SurgeLDAP Insecure Password Storage Vulnerability
| Bugtraq ID: | 8409 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 13 2003 12:00AM |
| Updated: | Aug 13 2003 12:00AM |
| Credit: | Discovery is credited to Ziv Kamir. |
| Vulnerable: |
NetWin SurgeLDAP 1.0 d |
| Not Vulnerable: |
NetWin SurgeLDAP 1.0 e |
Discussion
SurgeLDAP Insecure Password Storage Vulnerability
SurgeLDAP does not adequately secure password credentials. These credentials will be stored on the system hosting the server in plaintext and could be exposed to users with local access to the system.
SurgeLDAP does not adequately secure password credentials. These credentials will be stored on the system hosting the server in plaintext and could be exposed to users with local access to the system.
Solution / Fix
SurgeLDAP Insecure Password Storage Vulnerability
Solution:
The vendor has addressed this issue in SurgeLDAP 1.0e. Users are advised to upgrade as soon as possible.
NetWin SurgeLDAP 1.0 d
Solution:
The vendor has addressed this issue in SurgeLDAP 1.0e. Users are advised to upgrade as soon as possible.
NetWin SurgeLDAP 1.0 d
-
NetWin SurgeLDAP 1.0e
http://netwinsite.com/cgi-bin/keycgi.exe?cmd=download&product=surgelda p
References
SurgeLDAP Insecure Password Storage Vulnerability
References:
References:
- SurgeLDAP Homepage (NetWin)
- SurgeLDAP Update Information Page (NetWin)