CVE-2004-0823: High severity openldap OpenLDAP vulnerability
OpenLDAP 1.0 through 2.1.19, as used in Apple Mac OS 10.3.4 and 10.3.5 and possibly other operating systems, may allow certain authentication schemes to use hashed (crypt) passwords in the userPassword attribute as if they were plaintext passwords, which allows remote attackers to re-use hashed passwords without decrypting them.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0823?
CVE-2004-0823 has been classified as a medium severity vulnerability due to the potential for hashed passwords to be misused by remote attackers.
How do I fix CVE-2004-0823?
To fix CVE-2004-0823, it is recommended to upgrade OpenLDAP to version 2.1.20 or newer, which addresses this vulnerability.
What versions of OpenLDAP are affected by CVE-2004-0823?
CVE-2004-0823 affects OpenLDAP versions 1.0 through 2.1.19.
What platforms are affected by CVE-2004-0823?
CVE-2004-0823 has been reported on Apple Mac OS X versions 10.3.4 and 10.3.5, among other operating systems.
What type of vulnerability is CVE-2004-0823?
CVE-2004-0823 is an authentication vulnerability that allows the misuse of hashed passwords in the userPassword attribute.