CVE-2000-0748: Medium severity openldap OpenLDAP vulnerability
Published Sep 21, 2000
·Updated
OpenLDAP 1.2.11 and earlier improperly installs the ud binary with group write permissions, which could allow any user in that group to replace the binary with a Trojan horse.
Affected Software
5 affected components
openldap OpenLDAP=1.2.7
openldap OpenLDAP=1.2.8
openldap OpenLDAP=1.2.9
openldap OpenLDAP=1.2.10
openldap OpenLDAP=1.2.11
Remediation
Patch Available
Event History
Sep 21, 2000
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2000-0748?
CVE-2000-0748 is considered a high severity vulnerability due to the potential for unauthorized code execution.
2
How do I fix CVE-2000-0748?
To fix CVE-2000-0748, you should change the permissions of the ud binary to remove group write access.
3
Which versions of OpenLDAP are affected by CVE-2000-0748?
OpenLDAP versions 1.2.7, 1.2.8, 1.2.9, 1.2.10, and 1.2.11 are all affected by CVE-2000-0748.
4
What is the impact of CVE-2000-0748?
The impact of CVE-2000-0748 allows any user in the group to potentially replace the ud binary, leading to a security breach.
5
Is CVE-2000-0748 still a relevant vulnerability?
Yes, CVE-2000-0748 remains relevant for systems still running vulnerable versions of OpenLDAP.