pam_ldap and nss_ldap, when used with OpenLDAP and connecting to a slave using TLS, does not use TLS for the subsequent connection if the client is referred to a master, which may cause a password to be sent in cleartext and allows remote attackers to sniff the password.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libnss-ldapUpgrade libpam-ldap | Jul 30, 2024 | Jun 30, 2005 |
| Gentoo Linux | — | Upgrade sys-auth/nss_ldap.Upgrade sys-auth/pam_ldap. | Oct 30, 2017 | Jun 30, 2005 |
| Suse | — | Upgrade pam_ldapUpgrade openldap2-develUpgrade openldap2-devel-32bitUpgrade openldap2-devel-64bitUpgrade pam_ldap-32bitUpgrade pam_ldap-x86Upgrade openldap2-client-x86Upgrade openldap2-client-64bitUpgrade pam_ldap-64bitUpgrade openldap2-client-32bitUpgrade openldap2-client | Feb 17, 2015 | Jun 30, 2005 |
| Ubuntu | — | Upgrade libnss-ldap | Nov 8, 2024 | Jun 30, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub