#VU23423 Improper Authentication in OpenBSD - CVE-2019-19521
Published: December 5, 2019
OpenBSD
OpenBSD
Description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error in gen/auth_subr.c and gen/authenticate.c in libc, login/login.c and xenocara/app/xenodm/greeter/verify.c when handling authentication requests via the -schallenge username. A remote attacker can bypass authentication process for daemons that use vulnerable authentication scheme (e.g. smtpd, ldapd, or radiusd).
Successful exploitation of the vulnerability may allow an attacker to gain unauthorized access to the system.