OpenLDAP 1.0 through 2.1.19, as used in Apple Mac OS 10.3...
High severity
Unreviewed
Published
Apr 29, 2022
to the GitHub Advisory Database
•
Updated Apr 3, 2025
Description
Published by the National Vulnerability Database
Sep 7, 2004
Published to the GitHub Advisory Database
Apr 29, 2022
Last updated
Apr 3, 2025
OpenLDAP 1.0 through 2.1.19, as used in Apple Mac OS 10.3.4 and 10.3.5 and possibly other operating systems, may allow certain authentication schemes to use hashed (crypt) passwords in the userPassword attribute as if they were plaintext passwords, which allows remote attackers to re-use hashed passwords without decrypting them.
References