Vulnerability Name: | CVE-2002-0045 (CCN-7978) | ||||||||
Assigned: | 2002-01-14 | ||||||||
Published: | 2002-01-14 | ||||||||
Updated: | 2017-10-10 | ||||||||
Summary: | slapd in OpenLDAP 2.0 through 2.0.19 allows local users, and anonymous users before 2.0.8, to conduct a "replace" action on access controls without any values, which causes OpenLDAP to delete non-mandatory attributes that would otherwise be protected by ACLs. | ||||||||
CVSS v3 Severity: | 5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Data Manipulation | ||||||||
References: | Source: CALDERA Type: UNKNOWN CSSA-2002-001.0 Source: CCN Type: Caldera International, Inc. Security Advisory CSSA-2002-001.0 Linux - OpenLDAP attribute deletion problem Source: MITRE Type: CNA CVE-2002-0045 Source: CONECTIVA Type: UNKNOWN CLA-2002:459 Source: CCN Type: Conectiva Linux Announcement CLSA-2002:459 openldap Source: MANDRAKE Type: UNKNOWN MDKSA-2002:013 Source: CCN Type: Hewlett-Packard Company Security Bulletin HPSBTL0201-020 Security vulnerability in OpenLDAP packages. Source: CCN Type: RHSA-2002-014 Updated OpenLDAP packages available Source: CCN Type: openldap-announce Mailing List, Mon, 14 Jan 2002 13:59:23 -0800 OpenLDAP 2.0 Security Advisory Source: CONFIRM Type: Vendor Advisory http://www.openldap.org/lists/openldap-announce/200201/msg00002.html Source: CCN Type: OpenLDAP Web site Download Source: OSVDB Type: UNKNOWN 5395 Source: CCN Type: OSVDB ID: 5395 OpenLDAP slapd Object Attribute Deletion Source: REDHAT Type: UNKNOWN RHSA-2002:014 Source: BID Type: UNKNOWN 3945 Source: CCN Type: BID-3945 OpenLDAP Authenticated User Object Attribute Deletion Vulnerability Source: CCN Type: BID-3947 OpenLDAP Anonymous User Object Attribute Deletion Vulnerability Source: HP Type: UNKNOWN HPSBTL0201-020 Source: XF Type: UNKNOWN openldap-slapd-delete-attributes(7978) Source: XF Type: UNKNOWN openldap-slapd-delete-attributes(7978) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: ![]() | ||||||||
BACK |