First published: Wed May 05 2004(Updated: )
Kolab stores OpenLDAP passwords in plaintext in the slapd.conf file, which may be installed world-readable, which allows local users to gain privileges.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Kolab Groupware Server | =1.0 | |
openpkg openpkg | =2.0 | |
Kolab Groupware Server | =1.0.7 | |
Kolab Groupware Server | =1.0.6 | |
Kolab Groupware Server | =1.0.5 | |
Kolab Groupware Server | =1.0.3 | |
Kolab Groupware Server | =1.0.8 | |
Kolab Groupware Server | =1.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1997 is considered a high severity vulnerability due to the exposure of plaintext passwords.
To fix CVE-2004-1997, ensure that the slapd.conf file is not world-readable and consider using hashed passwords instead.
CVE-2004-1997 affects multiple versions of Kolab Groupware Server and Openpkg.
The risk of CVE-2004-1997 is that local users can read the configuration file and gain unauthorized access to sensitive information.
CVE-2004-1997 was reported in April 2004.