Secunia Logo
 
CVE Reference: CVE-2005-2069
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2005-2069

Description:
pam_ldap and nss_ldap, when used with OpenLDAP and connecting to a slave using TLS, does not use TLS for the subsequent connection if the client is referred to a master, which may cause a password to be sent in cleartext and allows remote attackers to sniff the password.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/21245

UBUNTU
  http://www.ubuntu.com/usn/usn-152-1

SAID
  Secunia Advisory: SA17233
  Secunia Advisory: SA17845
  Secunia Advisory: SA21520

REDHAT
  http://www.redhat.com/support/errata/RHSA-2005-751.html
  http://www.redhat.com/support/errata/RHSA-2005-767.html

OSVDB
  17692

MISC
  http://bugzilla.padl.com/show_bug.cgi?id=211
  http://bugzilla.padl.com/show_bug.cgi?id=210
  http://www.openldap.org/its/index.cgi/Incoming?id=3791

MANDRIVA
  http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2005:121

GENTOO
  http://www.gentoo.org/security/en/glsa/glsa-200507-13.xml

FULLDISC
  http://archives.neohapsis.com/archives/fulldisclosure/2005-07/0060.html

CONFIRM
  http://bugs.gentoo.org/show_bug.cgi?id=96767
  http://support.avaya.com/elmodocs2/security/ASA-2006-157.htm

BID
  14126
  14125


Return to the previous page.