Описание
nss-ldapd before 0.6.8 uses world-readable permissions for the /etc/nss-ldapd.conf file, which allows local users to obtain a cleartext password for the LDAP server by reading the bindpw field.
Ссылки
- Broken LinkExploit
- Broken Link
- Mailing ListPatch
- Broken Link
- Third Party Advisory
- Broken Link
- PatchThird Party Advisory
- Mailing List
- Mailing List
- Mailing List
- Mailing List
- Broken LinkThird Party AdvisoryVDB Entry
- Broken LinkExploit
- Broken Link
- Mailing ListPatch
- Broken Link
- Third Party Advisory
- Broken Link
- PatchThird Party Advisory
- Mailing List
Уязвимые конфигурации
EPSS
5.5 Medium
CVSS3
4.9 Medium
CVSS2
Дефекты
Связанные уязвимости
nss-ldapd before 0.6.8 uses world-readable permissions for the /etc/nss-ldapd.conf file, which allows local users to obtain a cleartext password for the LDAP server by reading the bindpw field.
nss-ldapd before 0.6.8 uses world-readable permissions for the /etc/ns ...
nss-ldapd before 0.6.8 uses world-readable permissions for the /etc/nss-ldapd.conf file, which allows local users to obtain a cleartext password for the LDAP server by reading the bindpw field.
Уязвимость пакета NSS-LDAP операционных систем Astra Linux и Debian GNU/Linux, позволяющая нарушителю получить пароль администратора сервера LDAP
Уязвимости операционной системы Debian GNU/Linux, позволяющие локальному злоумышленнику нарушить конфиденциальность защищаемой информации
EPSS
5.5 Medium
CVSS3
4.9 Medium
CVSS2