Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <Pine.GSO.4.51.0909161848210.7046@faron.mitre.org>
Date: Wed, 16 Sep 2009 18:54:51 -0400 (EDT)
From: "Steven M. Christey" <coley@...us.mitre.org>
To: oss-security@...ts.openwall.com
Subject: watch for LDAP anonymous binds and empty passwords


FYI, we've seen "LDAP anonymous binds and empty passwords" a couple times
in CVE, the latest being PostgreSQL (IDs forthcoming).  This smells like a
general vuln class to me, so developers may want to re-examine their LDAP
support.  CVE-2009-1905 and CVE-2007-6714 are examples.

I haven't investigated closely but the pattern may be that a blank
password can return successful authentication when anonymous binds are
allowed.  There's a relatively rare history of LDAP-specific vulns, which
suggests to me that not a lot of people have been looking for this.

- Steve

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.