First published: Tue Apr 29 2003(Updated: )
The LDAP name service (nsd) in IRIX 6.5.19 and earlier does not properly verify if the USERPASSWORD attribute has been provided by an LDAP server, which could allow attackers to log in without a password.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SGI IRIX | =6.5.9f | |
SGI IRIX | =6.5.16m | |
SGI IRIX | =6.5.6 | |
SGI IRIX | =6.5.4m | |
SGI IRIX | =6.5.17f | |
SGI IRIX | =6.5.3f | |
SGI IRIX | =6.5.1 | |
SGI IRIX | =6.5.14f | |
SGI IRIX | =6.5.4f | |
SGI IRIX | =6.5.13m | |
SGI IRIX | =6.5.12 | |
SGI IRIX | =6.5.17m | |
SGI IRIX | =6.5.2f | |
SGI IRIX | =6.5.7m | |
SGI IRIX | =6.5.10m | |
SGI IRIX | =6.5.13f | |
SGI IRIX | =6.5.16f | |
SGI IRIX | =6.5.19 | |
SGI IRIX | =6.5.9 | |
SGI IRIX | =6.5.17 | |
SGI IRIX | =6.5.19f | |
SGI IRIX | =6.5.9m | |
SGI IRIX | =6.5.10 | |
SGI IRIX | =6.5.15 | |
SGI IRIX | =6.5.15f | |
SGI IRIX | =6.5.18f | |
SGI IRIX | =6.5.2m | |
SGI IRIX | =6.5.11 | |
SGI IRIX | =6.5.11f | |
SGI IRIX | =6.5.14 | |
SGI IRIX | =6.5 | |
SGI IRIX | =6.5.11m | |
SGI IRIX | =6.5.14m | |
SGI IRIX | =6.5.2 | |
SGI IRIX | =6.5.5 | |
SGI IRIX | =6.5.8 | |
SGI IRIX | =6.5.10f | |
SGI IRIX | =6.5.13 | |
SGI IRIX | =6.5.16 | |
SGI IRIX | =6.5.18m | |
SGI IRIX | =6.5.3m | |
SGI IRIX | =6.5.6f | |
SGI IRIX | =6.5.6m | |
SGI IRIX | =6.5.19m | |
SGI IRIX | =6.5.4 | |
SGI IRIX | =6.5.7 | |
SGI IRIX | =6.5.7f | |
SGI IRIX | =6.5.12f | |
SGI IRIX | =6.5.12m | |
SGI IRIX | =6.5.15m | |
SGI IRIX | =6.5.18 | |
SGI IRIX | =6.5.3 | |
SGI IRIX | =6.5.5f | |
SGI IRIX | =6.5.5m | |
SGI IRIX | =6.5.8f | |
SGI IRIX | =6.5.8m | |
SGI IRIX | <=6.5.19 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0174 is considered a high severity vulnerability due to the potential for unauthorized access without a password.
The mitigation for CVE-2003-0174 involves upgrading to an unaffected version of IRIX that properly verifies the USERPASSWORD attribute.
CVE-2003-0174 affects IRIX versions 6.5.19 and earlier, including various specific subversions.
Exploitation of CVE-2003-0174 could facilitate unauthorized logins, potentially leading to data breaches or further system compromise.
CVE-2003-0174 is a known vulnerability that has been addressed and is less commonly encountered today, but it remains relevant for systems running vulnerable versions.