CVE-2007-3945: Medium severity RSBAC Rule Set Based Access Control vulnerability
Rule Set Based Access Control (RSBAC) before 1.3.5 does not properly use the Linux Kernel Crypto API for the Linux kernel 2.6.x, which allows context-dependent attackers to bypass authentication controls via unspecified vectors, possibly involving User Management password hashing and unchecked function return codes.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-3945?
CVE-2007-3945 is considered a high-severity vulnerability that allows attackers to bypass authentication controls.
How do I fix CVE-2007-3945?
To fix CVE-2007-3945, you should upgrade to RSBAC version 1.3.5 or later.
What software is affected by CVE-2007-3945?
CVE-2007-3945 affects versions of RSBAC before 1.3.5 and Linux kernel versions from 2.6.0 up to 2.6.39.4.
What are the potential impacts of exploiting CVE-2007-3945?
Exploitation of CVE-2007-3945 can lead to unauthorized access and privilege escalation on systems using vulnerable software.
Are there any workarounds for CVE-2007-3945?
There are no effective workarounds for CVE-2007-3945; updating the software is the recommended method to mitigate the vulnerability.