Description
The pam_lsass library in Likewise Open 5.4 and CIFS 5.4 before build 8046, and 6.0 before build 8234, as used in HP StorageWorks X9000 Network Storage Systems and possibly other products, uses "SetPassword logic" when running as part of a root service, which allows remote attackers to bypass authentication for a Likewise Security Authority (lsassd) account whose password is marked as expired.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2010-0858 | The pam_lsass library in Likewise Open 5.4 and CIFS 5.4 before build 8046, and 6.0 before build 8234, as used in HP StorageWorks X9000 Network Storage Systems and possibly other products, uses "SetPassword logic" when running as part of a root service, which allows remote attackers to bypass authentication for a Likewise Security Authority (lsassd) account whose password is marked as expired. |
Ubuntu USN |
USN-964-1 | Likewise Open vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: canonical
Published:
Updated: 2024-08-07T00:59:39.384Z
Reserved: 2010-03-03T00:00:00.000Z
Link: CVE-2010-0833
No data.
Status : Modified
Published: 2010-07-28T12:48:51.917
Modified: 2026-04-29T01:13:23.040
Link: CVE-2010-0833
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Ubuntu USN