Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2002-0374
Description:Format string vulnerability in the logging function for the pam_ldap PAM LDAP module before version 144 allows attackers to execute arbitrary code via format strings in the configuration file name.
Test IDs: 1.3.6.1.4.1.25623.1.0.51231  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2002-0374
BugTraq ID: 4679
http://www.securityfocus.com/bid/4679
Bugtraq: 20020506 ldap vulnerabilities (Google Search)
Bugtraq: 20021030 GLSA: pam_ldap (Google Search)
http://marc.info/?l=bugtraq&m=103601912505261&w=2
Caldera Security Advisory: CSSA-2002-041.0
ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-041.0.txt
http://www.mandrakesoft.com/security/advisories?name=MDKSA-2002:075
RedHat Security Advisories: RHSA-2002:084
http://www.redhat.com/support/errata/RHSA-2002-084.html
RedHat Security Advisories: RHSA-2002:141
http://www.redhat.com/support/errata/RHSA-2002-141.html
RedHat Security Advisories: RHSA-2002:175
http://www.redhat.com/support/errata/RHSA-2002-175.html
RedHat Security Advisories: RHSA-2002:180
http://www.redhat.com/support/errata/RHSA-2002-180.html
http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0053.html
XForce ISS Database: pamldap-config-format-string(9018)
http://www.iss.net/security_center/static/9018.php




© 1998-2025 E-Soft Inc. All rights reserved.