First published: Mon Jul 23 2007(Updated: )
Rule Set Based Access Control (RSBAC) before 1.3.5 does not properly use the Linux Kernel Crypto API for the Linux kernel 2.6.x, which allows context-dependent attackers to bypass authentication controls via unspecified vectors, possibly involving User Management password hashing and unchecked function return codes.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
RSBAC (Rule Set Based Access Control) | <1.3.5 | |
Linux Kernel | >=2.6.0<=2.6.39.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3945 is considered a high-severity vulnerability that allows attackers to bypass authentication controls.
To fix CVE-2007-3945, you should upgrade to RSBAC version 1.3.5 or later.
CVE-2007-3945 affects versions of RSBAC before 1.3.5 and Linux kernel versions from 2.6.0 up to 2.6.39.4.
Exploitation of CVE-2007-3945 can lead to unauthorized access and privilege escalation on systems using vulnerable software.
There are no effective workarounds for CVE-2007-3945; updating the software is the recommended method to mitigate the vulnerability.