Candidate: CVE-2014-3999 PublicDate: 2018-04-10 15:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3999 http://www.openwall.com/lists/oss-security/2014/06/09/2 Description: The Horde_Ldap library before 2.0.6 for Horde allows remote attackers to bypass authentication by leveraging knowledge of the LDAP bind user DN. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Matthew Daley Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H [8.1 HIGH] Patches_php-horde-ldap: upstream: https://github.com/horde/horde/commit/4c3e18f1724ab39bfef10c189a5b52036a744d55 upstream_php-horde-ldap: released (2.0.6) lucid_php-horde-ldap: DNE precise_php-horde-ldap: DNE precise/esm_php-horde-ldap: DNE saucy_php-horde-ldap: ignored (reached end-of-life) trusty_php-horde-ldap: ignored (reached end-of-life) trusty/esm_php-horde-ldap: DNE (trusty was needed) utopic_php-horde-ldap: ignored (reached end-of-life) vivid_php-horde-ldap: ignored (reached end-of-life) vivid/stable-phone-overlay_php-horde-ldap: DNE vivid/ubuntu-core_php-horde-ldap: DNE wily_php-horde-ldap: ignored (reached end-of-life) xenial_php-horde-ldap: not-affected (2.0.6-1) yakkety_php-horde-ldap: ignored (reached end-of-life) zesty_php-horde-ldap: ignored (reached end-of-life) artful_php-horde-ldap: ignored (reached end-of-life) bionic_php-horde-ldap: not-affected (2.0.6-1) cosmic_php-horde-ldap: not-affected (2.0.6-1) disco_php-horde-ldap: not-affected (2.0.6-1) devel_php-horde-ldap: not-affected (2.0.6-1)