CVE-2007-3193
Publication date 12 June 2007
Last updated 24 July 2024
Ubuntu priority
lib/WikiUser/LDAP.php in PhpWiki before 1.3.13p1, when the configuration lacks a nonzero PASSWORD_LENGTH_MINIMUM, might allow remote attackers to bypass authentication via an empty password, which causes ldap_bind to return true when used with certain LDAP implementations.
Status
Package | Ubuntu Release | Status |
---|---|---|
phpwiki | 9.10 karmic |
Fixed 1.3.12p3-6.1
|
9.04 jaunty |
Fixed 1.3.12p3-6.1
|
|
8.10 intrepid |
Fixed 1.3.12p3-6.1
|
|
8.04 LTS hardy |
Fixed 1.3.12p3-6.1
|
|
7.10 gutsy |
Fixed 1.3.12p3-6.1
|
|
7.04 feisty | Ignored end of life, was needed | |
6.10 edgy | Ignored end of life, was needed | |
6.06 LTS dapper | Ignored end of life |