Candidate: CVE-2011-0002 PublicDate: 2011-01-22 22:00:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0002 https://fedorahosted.org/libuser/browser/NEWS?rev=libuser-0.57 Description: libuser before 0.57 uses a cleartext password value of (1) !! or (2) x for new LDAP user accounts, which makes it easier for remote attackers to obtain access by specifying one of these values. Ubuntu-Description: Notes: Bugs: https://bugzilla.redhat.com/643227 Priority: medium Discovered-by: Assigned-to: CVSS: Patches_libuser: upstream_libuser: released (0.57) dapper_libuser: ignored (reached end-of-life) hardy_libuser: ignored (reached end-of-life) karmic_libuser: ignored (reached end-of-life) lucid_libuser: ignored (reached end-of-life) maverick_libuser: ignored (reached end-of-life) natty_libuser: not-affected (1:0.56.9.dfsg.1-1.1ubuntu1) oneiric_libuser: not-affected (1:0.56.9.dfsg.1-1.1ubuntu1) precise_libuser: not-affected (1:0.56.9.dfsg.1-1.1ubuntu1) quantal_libuser: not-affected (1:0.56.9.dfsg.1-1.1ubuntu1) raring_libuser: not-affected (1:0.56.9.dfsg.1-1.1ubuntu1) saucy_libuser: not-affected (1:0.56.9.dfsg.1-1.1ubuntu1) devel_libuser: not-affected (1:0.56.9.dfsg.1-1.1ubuntu1)