CVE-2007-3945
Last modified
CVE-2007-3945 is a vulnerability of currently unknown severity. Rule Set Based Access Control (RSBAC) before 1.3.5 does not properly use the Linux Kernel Crypto API for the Linux kernel 2.6.x, which allows context-dependent attackers to bypass authentication controls via unspecified vectors, possibly involving User Management password hashing and unchecked function return codes.. EPSS estimates a 2.48% chance of exploitation in the next 30 days.
Description
Rule Set Based Access Control (RSBAC) before 1.3.5 does not properly use the Linux Kernel Crypto API for the Linux kernel 2.6.x, which allows context-dependent attackers to bypass authentication controls via unspecified vectors, possibly involving User Management password hashing and unchecked function return codes.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Rsbac | Rule Set Based Access Control | < 1.3.5 |
References
- http://download.rsbac.org/code/1.3.5/changes-1.3.5.txtVendor Advisory
- http://secunia.com/advisories/26147Broken Link
- http://securityreason.com/securityalert/2911Third Party Advisory
- http://www.securityfocus.com/archive/1/474161/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/25001Broken Link, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2007/2610URL Repurposed
- http://download.rsbac.org/code/1.3.5/changes-1.3.5.txtVendor Advisory
- http://secunia.com/advisories/26147Broken Link
- http://securityreason.com/securityalert/2911Third Party Advisory
- http://www.securityfocus.com/archive/1/474161/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/25001Broken Link, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2007/2610URL Repurposed
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-3945?
How severe is CVE-2007-3945?
How do I fix CVE-2007-3945?
Are you affected by CVE-2007-3945?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
