PyPI: products-ldapuserfolder
CVE-2010-2944
Safety vulnerability ID: SFTY-20100820-92615
Safety legacy ID: pyup.io-26023
Products.ldapuserfolder version 2.20 includes a fix for CVE-2010-2944: The authenticate function in LDAPUserFolder/LDAPUserFolder.py in zope-ldapuserfolder 2.9-1 does not verify the password for the emergency account, which allows remote attackers to gain privileges. https://github.com/dataflake/Products.LDAPUserFolder/commit/246257dbe5f73a6fd3c3e597814038977004cdd7
Overview
Products.ldapuserfolder version 2.20 includes a fix for CVE-2010-2944: The authenticate function in LDAPUserFolder/LDAPUserFolder.py in zope-ldapuserfolder 2.9-1 does not verify the password for the emergency account, which allows remote attackers to gain privileges. https://github.com/dataflake/Products.LDAPUserFolder/commit/246257dbe5f73a6fd3c3e597814038977004cdd7
Advisory
Products.ldapuserfolder version 2.20 includes a fix for CVE-2010-2944: The authenticate function in LDAPUserFolder/LDAPUserFolder.py in zope-ldapuserfolder 2.9-1 does not verify the password for the emergency account, which allows remote attackers to gain privileges. https://github.com/dataflake/Products.LDAPUserFolder/commit/246257dbe5f73a6fd3c3e597814038977004cdd7
How to Fix
Mitigation and Workarounds
---
Vulnerable Functions
Functions linked to known vulnerabilities.
References
- https://getsafety.com/vulnerabilities/SFTY-20100820-92615/CVE-2010-2944
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=593466
- http://secunia.com/advisories/41022
- http://www.openwall.com/lists/oss-security/2010/08/18/3
- http://www.openwall.com/lists/oss-security/2010/08/19/7
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2944
Verified by Safety
Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.
Learn more