Lucene search

K
ubuntucveUbuntu.comUB:CVE-2010-2944
HistoryAug 20, 2010 - 12:00 a.m.

CVE-2010-2944

2010-08-2000:00:00
ubuntu.com
ubuntu.com
4

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.008

Percentile

81.8%

The authenticate function in LDAPUserFolder/LDAPUserFolder.py in
zope-ldapuserfolder 2.9-1 does not verify the password for the emergency
account, which allows remote attackers to gain privileges.

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.008

Percentile

81.8%