CVE Database
/

CVE-2005-2069

Back to search

CVE-2005-2069

Published: Jun 29, 2005

Modified: Aug 7, 2024

PUBLISHED

Description

pam_ldap and nss_ldap, when used with OpenLDAP and connecting to a slave using TLS, does not use TLS for the subsequent connection if the client is referred to a master, which may cause a password to be sent in cleartext and allows remote attackers to sniff the password.

VendorProductVersions

n/a

n/a

affected
n/a

References

GLSA-2005-07-13
vendor-advisory
x_refsource_GENTOO
14126
vdb-entry
x_refsource_BID
RHSA-2005:751
vendor-advisory
x_refsource_REDHAT
17692
vdb-entry
x_refsource_OSVDB
17845
third-party-advisory
x_refsource_SECUNIA
14125
vdb-entry
x_refsource_BID
oval:org.mitre.oval:def:9445
vdb-entry
signature
x_refsource_OVAL
MDKSA-2005:121
vendor-advisory
x_refsource_MANDRIVA
21520
third-party-advisory
x_refsource_SECUNIA
RHSA-2005:767
vendor-advisory
x_refsource_REDHAT
17233
third-party-advisory
x_refsource_SECUNIA
USN-152-1
vendor-advisory
x_refsource_UBUNTU

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now