Описание
nslcd/pam.c in the nss-pam-ldapd 0.8.0 PAM module returns a success code when a user is not found in LDAP, which allows remote attackers to bypass authentication.
| Релиз | Статус | Примечание |
|---|---|---|
| dapper | DNE | |
| devel | not-affected | 0.8.0 only |
| hardy | DNE | |
| karmic | DNE | |
| lucid | not-affected | 0.8.0 only |
| maverick | not-affected | 0.8.0 only |
| upstream | released | 0.8.1 |
Показывать по
Ссылки на источники
EPSS
6.8 Medium
CVSS2
Связанные уязвимости
nslcd/pam.c in the nss-pam-ldapd 0.8.0 PAM module returns a success code when a user is not found in LDAP, which allows remote attackers to bypass authentication.
nslcd/pam.c in the nss-pam-ldapd 0.8.0 PAM module returns a success co ...
nslcd/pam.c in the nss-pam-ldapd 0.8.0 PAM module returns a success code when a user is not found in LDAP, which allows remote attackers to bypass authentication.
Уязвимость PAM-модуля предоставления NSS-данных для LDAP-сервера nss-pam-ldapd, позволяющая нарушителю обойти процедуру аутентификации
EPSS
6.8 Medium
CVSS2