CVE-2010-2940
30.08.2010, 20:00
The auth_send function in providers/ldap/ldap_auth.c in System Security Services Daemon (SSSD) 1.3.0, when LDAP authentication and anonymous bind are enabled, allows remote attackers to bypass the authentication requirements of pam_authenticate via an empty password.Enginsight
Vendor | Product | Version |
---|---|---|
fedoraproject | sssd | 1.3.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration