Lucene search

K
cvelistMitreCVELIST:CVE-2019-19521
HistoryDec 04, 2019 - 11:33 p.m.

CVE-2019-19521

2019-12-0423:33:35
mitre
www.cve.org
2

9.7 High

AI Score

Confidence

High

0.015 Low

EPSS

Percentile

86.8%

libc in OpenBSD 6.6 allows authentication bypass via the -schallenge username, as demonstrated by smtpd, ldapd, or radiusd. This is related to gen/auth_subr.c and gen/authenticate.c in libc (and login/login.c and xenocara/app/xenodm/greeter/verify.c).

9.7 High

AI Score

Confidence

High

0.015 Low

EPSS

Percentile

86.8%