lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Date: Wed, 18 Jul 2007 08:36:58 -0700
From: Chris Travers <chris@...atrontech.com>
To: bugtraq@...urityfocus.com
Subject: Security Advisory:  Login bypass in LedgerSMB 1.2.0 through 1.2.6

A security issue has been found which allows an unauthenticated user to 
bypass the authentication system in LedgerSMB 1.2.0 through 1.2.6.

Severity:  Highly Critical
Versions affected:  1.2.0 through 1.2.6
Status: Vendor solution available (upgrade to 1.2.7)
Effect: Authentication bypass.
Required knowledge:  A valid username for any user.
Related Advisory ID's:  Bugtraq ID: 24940
No CVE has yet been assigned.
Exploit complexity:  Simple


This is listed as highly critical because it could be used to access the 
entire application masquerading as a different user than one is 
authorized to use.  This is a serious risk in any financial system as it 
could be a vector for embezzlement and covering up dishonest activities.

Origins and Information:
The problem occurs because of a flaw in the redirect code which was 
replaced in order to support additional environments.  The redirection 
code in this case can be accessed through the login module and tricked 
into providing access without proper authentication.

Exploits can be performed by setting the action variable in the http 
request to "redirect" with a callback variable set to the escaped URL 
representing the desired action.

Not affected:
LedgerSMB prior to 1.2.0 or after 1.2.6
SQL-Ledger (any version)

Solution:
Upgrade to LedgerSMB 1.2.7

Credit:
This was discovered by a core member of the LedgerSMB team who has asked 
to remain anonymous.  This disclosure is intended to help those who 
manufacture security products or are responsible for the security of 
their networks.  All questions regarding more information on this 
vulnerability can be directed to Chris Travers ( chris@...atrontech.com 
<mailto:chris@...atrontech.com> or chris.travers@...il.com 
<mailto:chris.travers@...il.com>).


View attachment "chris.vcf" of type "text/x-vcard" (172 bytes)

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ