CVE-2007-3945
Rule Set Based Access Control (RSBAC) before 1.3.5 does not properly use the Linux Kernel Crypto API for the Linux kernel 2.6.x, which allows context-dependent attackers to bypass authentication controls via unspecified vectors, possibly involving User…
Does this matter?
Lower severity and a low EPSS score (2.48%). Track it; it rarely justifies an emergency change on its own.
Description
Rule Set Based Access Control (RSBAC) before 1.3.5 does not properly use the Linux Kernel Crypto API for the Linux kernel 2.6.x, which allows context-dependent attackers to bypass authentication controls via unspecified vectors, possibly involving User Management password hashing and unchecked function return codes.
- CVSS 2.0
- 6.4 MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
- EPSS
- 2.48% probability · 84th percentile
- CISA KEV
- Not listed
- Affected
- rsbac/rule set based access control
- Source
- cve@mitre.org
References
- http://download.rsbac.org/code/1.3.5/changes-1.3.5.txtVendor Advisory
- http://secunia.com/advisories/26147Broken Link
- http://securityreason.com/securityalert/2911Third Party Advisory
- http://www.securityfocus.com/archive/1/474161/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/25001Broken Link, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2007/2610URL Repurposed
- http://download.rsbac.org/code/1.3.5/changes-1.3.5.txtVendor Advisory
- http://secunia.com/advisories/26147Broken Link
- http://securityreason.com/securityalert/2911Third Party Advisory
- http://www.securityfocus.com/archive/1/474161/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/25001Broken Link, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2007/2610URL Repurposed
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.