libuser before 0.57 uses a cleartext password value of (1) !! or (2) x for new LDAP user accounts, which makes it easier for remote attackers to obtain access by specifying one of these values.
CVSS Details
- CVSS 3.1 Base Score: 9.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade libuser-develUpgrade libuser | Dec 1, 2016 | Jan 22, 2011 |
| Debian | — | Upgrade libuser | Jul 30, 2024 | Jan 22, 2011 |
| Oracle_linux | — | Upgrade libuser-pythonUpgrade libuser-develUpgrade libuser | Oct 16, 2024 | Jan 22, 2011 |
| Redhat_linux | — | — | Jul 9, 2025 | Jan 10, 2011 |
| Vmsa 2011 0013 | — | Upgrade VMware ESX 4.0 to build number 660575Upgrade VMware ESX 4.1 to build number 502767 | Nov 22, 2011 | Jan 22, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub