CVE-2007-3945

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
23/07/2007
Last modified:
20/06/2023

Description

Rule Set Based Access Control (RSBAC) before 1.3.5 does not properly use the Linux Kernel Crypto API for the Linux kernel 2.6.x, which allows context-dependent attackers to bypass authentication controls via unspecified vectors, possibly involving User Management password hashing and unchecked function return codes.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:rsbac:rule_set_based_access_control:*:*:*:*:*:*:*:* 1.3.5 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 2.6.0 (including) 2.6.39.4 (including)