Lucene search

K
prionPRIOn knowledge basePRION:CVE-2019-19521
HistoryDec 05, 2019 - 12:15 a.m.

Authentication flaw

2019-12-0500:15:00
PRIOn knowledge base
www.prio-n.com
21

9.4 High

AI Score

Confidence

High

0.015 Low

EPSS

Percentile

86.8%

libc in OpenBSD 6.6 allows authentication bypass via the -schallenge username, as demonstrated by smtpd, ldapd, or radiusd. This is related to gen/auth_subr.c and gen/authenticate.c in libc (and login/login.c and xenocara/app/xenodm/greeter/verify.c).

CPENameOperatorVersion
openbsdeq6.6

9.4 High

AI Score

Confidence

High

0.015 Low

EPSS

Percentile

86.8%