CVE Database
/

CVE-2006-5170

Back to search

CVE-2006-5170

Published: Oct 4, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

pam_ldap in nss_ldap on Red Hat Enterprise Linux 4, Fedora Core 3 and earlier, and possibly other distributions does not return an error condition when an LDAP directory server responds with a PasswordPolicyResponse control response, which causes the pam_authenticate function to return a success code even if authentication has failed, as originally reported for xscreensaver.

VendorProductVersions

n/a

n/a

affected
n/a

References

1017153
vdb-entry
x_refsource_SECTRACK
RHSA-2006:0719
vendor-advisory
x_refsource_REDHAT
22682
third-party-advisory
x_refsource_SECUNIA
20061005 rPSA-2006-0183-1 nss_ldap
mailing-list
x_refsource_BUGTRAQ
2006-0061
vendor-advisory
x_refsource_TRUSTIX
20880
vdb-entry
x_refsource_BID
22685
third-party-advisory
x_refsource_SECUNIA
MDKSA-2006:201
vendor-advisory
x_refsource_MANDRIVA
SUSE-SR:2006:027
vendor-advisory
x_refsource_SUSE
22869
third-party-advisory
x_refsource_SECUNIA
22694
third-party-advisory
x_refsource_SECUNIA
23132
third-party-advisory
x_refsource_SECUNIA
GLSA-200612-19
vendor-advisory
x_refsource_GENTOO
23428
third-party-advisory
x_refsource_SECUNIA
oval:org.mitre.oval:def:10418
vdb-entry
signature
x_refsource_OVAL
DSA-1203
vendor-advisory
x_refsource_DEBIAN
22696
third-party-advisory
x_refsource_SECUNIA
ADV-2006-4319
vdb-entry
x_refsource_VUPEN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now