The LDAP name service (nsd) in IRIX 6.5.19 and earlier does not properly verify if the USERPASSWORD attribute has been provided by an LDAP server, which could allow attackers to log in without a password.
The product does not properly verify that the source of data or communication is valid.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/7442 | patch vendor advisory vdb entry third party advisory broken link |
https://exchange.xforce.ibmcloud.com/vulnerabilities/11860 | vdb entry third party advisory |
ftp://patches.sgi.com/support/free/security/advisories/20030407-01-P | broken link patch vendor advisory |
http://www.ciac.org/ciac/bulletins/n-084.shtml | third party advisory government resource broken link |