[Tickets #1643] NEW: uid filter patch breaks LDAP user enumeration

bugs at bugs.horde.org bugs at bugs.horde.org
Tue Mar 29 10:13:45 PST 2005


DO NOT REPLY TO THIS MESSAGE. THIS EMAIL ADDRESS IS NOT MONITORED.

Ticket URL: http://bugs.horde.org/ticket/?id=1643
-----------------------------------------------------------------------
 Ticket             | 1643
 Created By         | kevin_myer at iu13.org
 Summary            | uid filter patch breaks LDAP user enumeration
 Queue              | Horde Base
 Version            | 3.0.4-RC2
 State              | Unconfirmed
 Priority           | 1. Low
 Type               | Bug
 Owners             | 
+New Attachment     | ldap.diff
-----------------------------------------------------------------------


kevin_myer at iu13.org (2005-03-29 10:13) wrote:

If using anything beside the uid attribute for the DN, the patch to
lib/Horde/Auth/ldap.php breaks user enumeration.

The argument to the array should be something like $this->_params['uid'] and
not hardcoded to 'uid'.




More information about the bugs mailing list