FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2009-1596

This CVE name corresponds to:

Entered Topic
2009-05-04 openfire -- Openfire No Password Changes Security Bypass

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2009-1596
Phase Assigned(20090511)

Description

Ignite Realtime Openfire before 3.6.5 does not properly implement the register.password (aka canChangePassword) console configuration setting, which allows remote authenticated users to bypass intended policy and change their own passwords via a passwd_change IQ packet.

References

Source Reference
CONFIRM http://www.igniterealtime.org/community/message/190280
CONFIRM http://www.igniterealtime.org/issues/browse/JM-1532
BID 34804
OSVDB 54189
SECUNIA 34984
XF openfire-nopassword-security-bypass(50291)