CVE-2011-0002

NameCVE-2011-0002
Descriptionlibuser before 0.57 uses a cleartext password value of (1) !! or (2) x for new LDAP user accounts, which makes it easier for remote attackers to obtain access by specifying one of these values.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs610034

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libuser (PTS)buster1:0.62~dfsg-0.1fixed
bullseye1:0.62~dfsg-0.4fixed
bookworm1:0.64~dfsg-1fixed
sid, trixie1:0.64~dfsg-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libusersource(unstable)1:0.56.9.dfsg.1-1.1610034

Search for package or bug name: Reporting problems