Secunia Logo
Netsikker nu! 2008
 
Debian update for libpam-ldap
Secunia Advisory: SA16588
Release Date: 2005-08-26
Popularity: 5,824 views

Critical:
Less critical
Impact: Security Bypass
Where: From remote
Solution Status: Vendor Patch

OS:Debian GNU/Linux 3.1
Debian GNU/Linux unstable alias sid

Subscribe: Instant alerts on relevant vulnerabilities

CVE reference:CVE-2005-2641


Description:
Debian has issued an update for libpam-ldap. This fixes a security issue, which can be exploited by malicious people to bypass certain security restrictions.

For more information:
SA16518

Solution:
Apply updated packages.

-- Debian GNU/Linux 3.1 alias sarge --

Source archives:

http://security.debian.org/pool/updat...bpam-ldap/libpam-ldap_178-1sarge1.dsc
Size/MD5 checksum: 672 d669aa6f0c46e637446594350af42cc8
http://security.debian.org/pool/updat...-ldap/libpam-ldap_178-1sarge1.diff.gz
Size/MD5 checksum: 19528 2924e1797c39f05e37bafaa761ca2c96
http://security.debian.org/pool/updat...bpam-ldap/libpam-ldap_178.orig.tar.gz
Size/MD5 checksum: 127074 222186c498d24a7035e8a7494fc0797d

Alpha architecture:

http://security.debian.org/pool/updat...dap/libpam-ldap_178-1sarge1_alpha.deb
Size/MD5 checksum: 59270 a6960b38195110ce4c555cf89e2cc752

AMD64 architecture:

http://security.debian.org/pool/updat...dap/libpam-ldap_178-1sarge1_amd64.deb
Size/MD5 checksum: 56984 e14265169b634d5c6ee243cc1b8cc410

ARM architecture:

http://security.debian.org/pool/updat...-ldap/libpam-ldap_178-1sarge1_arm.deb
Size/MD5 checksum: 55852 6a4f6cee9779f0bd45511fe4dda02245

Intel IA-32 architecture:

http://security.debian.org/pool/updat...ldap/libpam-ldap_178-1sarge1_i386.deb
Size/MD5 checksum: 57406 eafc9a4a7ee19e173cca4069ce822938

Intel IA-64 architecture:

http://security.debian.org/pool/updat...ldap/libpam-ldap_178-1sarge1_ia64.deb
Size/MD5 checksum: 65072 4de0ae7288d74d2eb7708424603b50f6

HP Precision architecture:

http://security.debian.org/pool/updat...ldap/libpam-ldap_178-1sarge1_hppa.deb
Size/MD5 checksum: 60552 3eb44b515aa7fdd05376520de7ab99dd

Motorola 680x0 architecture:

http://security.debian.org/pool/updat...ldap/libpam-ldap_178-1sarge1_m68k.deb
Size/MD5 checksum: 55992 41341e49ab1dd2b2f7c6e1365186579f

Big endian MIPS architecture:

http://security.debian.org/pool/updat...ldap/libpam-ldap_178-1sarge1_mips.deb
Size/MD5 checksum: 56360 3d4ad06491d46a8cbcc80236dd3edd08

Little endian MIPS architecture:

http://security.debian.org/pool/updat...ap/libpam-ldap_178-1sarge1_mipsel.deb
Size/MD5 checksum: 56292 258c5c9a7b9b725c305c122a6843a4d9

PowerPC architecture:

http://security.debian.org/pool/updat...p/libpam-ldap_178-1sarge1_powerpc.deb
Size/MD5 checksum: 57216 933ce656b572a6faaf1273eb2a5bba41

IBM S/390 architecture:

http://security.debian.org/pool/updat...ldap/libpam-ldap_178-1sarge1_s390.deb
Size/MD5 checksum: 57370 217d4f36380fcecec41236ed53f9a2d6

Sun Sparc architecture:

http://security.debian.org/pool/updat...dap/libpam-ldap_178-1sarge1_sparc.deb
Size/MD5 checksum: 56934 411656469f51633a23ae7e9961786fca

-- Debian GNU/Linux unstable alias sid --

Fixed in version 178-1sarge1.

Original Advisory:
http://www.debian.org/security/2005/dsa-785

Other References:
SA16518:
http://secunia.com/advisories/16518/


Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. VMware ESX Server Sun Java JDK / JRE Multiple Vulnerabilities // 47 views
2. phpBB Avatar Script Insertion Vulnerability // 46 views
3. Microsoft Windows Vista Page Fault Handling Denial of Service // 46 views
4. VMware VirtualCenter Multiple Vulnerabilities // 41 views
5. VMware ESX / ESXi "JMP" Privilege Escalation Vulnerability // 38 views
6. Serv-U File Renaming Directory Traversal and STOU Denial of Service // 33 views
7. Nucleus EUC-JP Cross-Site Scripting Vulnerability // 33 views
8. Subdreamer Light Global Variables SQL Injection Vulnerability // 32 views
9. JMweb MP3 Script "src" File Inclusion Vulnerabilities // 32 views
10. AmpJuke "special" SQL Injection Vulnerability // 32 views