nss-pam-ldapd before 0.7.18 and 0.8.x before 0.8.11 allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code by performing a name lookup on an application with a large number of open file descriptors, which triggers a stack-based buffer overflow related to incorrect use of the FD_SET macro.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade nss-pam-ldapd | Dec 1, 2016 | Mar 5, 2013 |
| Debian | — | Upgrade nss-pam-ldapd | Jul 30, 2024 | Mar 5, 2013 |
| Freebsd | — | Upgrade nss-pam-ldapd | Dec 10, 2025 | Feb 20, 2013 |
| Oracle_linux | — | Upgrade nss-pam-ldapd | Oct 16, 2024 | Mar 4, 2013 |
| Suse | — | Upgrade nss-pam-ldapdUpgrade nss-pam-ldapd-debuginfo-32bitUpgrade nss-pam-ldapd-debuginfoUpgrade nss-pam-ldapd-x86Upgrade nss-pam-ldapd-debuginfo-x86Upgrade nss-pam-ldapd-32bitUpgrade nss-pam-ldapd-debugsource | Dec 12, 2013 | Mar 5, 2013 |
| Ubuntu | — | Upgrade nss-pam-ldapd | Nov 19, 2024 | Mar 5, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub