Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2007-5373
Description:ldapscripts 1.4 and 1.7 sends a password as a command line argument when calling some LDAP programs, which might allow local users to read the password by listing the process and its arguments, as demonstrated by a call to ldappasswd in the _changepassword function.
Test IDs: 1.3.6.1.4.1.25623.1.0.60569   1.3.6.1.4.1.25623.1.0.58779  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2007-5373
BugTraq ID: 25982
http://www.securityfocus.com/bid/25982
Debian Security Information: DSA-1517 (Google Search)
http://www.debian.org/security/2008/dsa-1517
http://secunia.com/advisories/27111
http://secunia.com/advisories/29395
XForce ISS Database: ldapscripts-commandline-info-disclosure(37029)
https://exchange.xforce.ibmcloud.com/vulnerabilities/37029




© 1998-2025 E-Soft Inc. All rights reserved.