| Vulnerability Name: | CVE-2000-0956 (CCN-5427) | ||||||||
| Assigned: | 2000-10-26 | ||||||||
| Published: | 2000-10-26 | ||||||||
| Updated: | 2017-10-10 | ||||||||
| Summary: | cyrus-sasl before 1.5.24 in Red Hat Linux 7.0 does not properly verify the authorization for a local user, which could allow the users to bypass specified access restrictions. | ||||||||
| CVSS v3 Severity: | 5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
| CVSS v2 Severity: | 4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
| Vulnerability Type: | CWE-Other | ||||||||
| Vulnerability Consequences: | Gain Access | ||||||||
| References: | Source: CCN Type: Red Hat Bugzilla Bug 18968 Bugzilla Bug - 18968 Source: MITRE Type: CNA CVE-2000-0956 Source: CCN Type: RHSA-2000-094 Updated cyrus-sasl packages available for Red Hat Linux 7 Source: CCN Type: OSVDB ID: 1627 Cyrus SASL (cyrus-sasl) User Authentication Restriction Bypass Source: REDHAT Type: Patch, Vendor Advisory RHSA-2000:094 Source: BID Type: Patch, Vendor Advisory 1875 Source: CCN Type: BID-1875 RedHat 7.0 Cyrus-SASL Authorization Vulnerability Source: XF Type: UNKNOWN cyrus-sasl-gain-access(5427) Source: XF Type: UNKNOWN cyrus-sasl-gain-access(5427) | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||