| |||||||||||||
| Test ID: | 1.3.6.1.4.1.25623.1.0.54405 |
| Category: | Ubuntu Local Security Checks |
| Title: | Ubuntu USN-152-1 (libnss-ldap) |
| Summary: | Ubuntu USN-152-1 (libnss-ldap) |
| Description: | The remote host is missing an update to libnss-ldap announced via advisory USN-152-1. A security issue affects the following Ubuntu releases: Ubuntu 4.10 (Warty Warthog) Ubuntu 5.04 (Hoary Hedgehog) The following packages are affected: libnss-ldap libpam-ldap slapd Andrea Barisani discovered a flaw in the SSL handling of pam-ldap and libnss-ldap. When a client connected to a slave LDAP server using SSL, the slave server did not use SSL as well when contacting the LDAP master server. This caused passwords and other confident information to be transmitted unencrypted between the slave and the master. Solution: On Ubuntu 4.10, the problem can be corrected by upgrading the affected packages to version 2.1.30-2ubuntu4.1 (slapd), 164-2ubuntu0.1 (libpam-ldap), and 220-1ubuntu0.1 (libnss-ldap). On Ubuntu 5.04, the problem can be corrected by upgrading the affected packages to version 2.1.30-3ubuntu3.1 (slapd), 169-1ubuntu0.1 (libpam-ldap), and 220-1ubuntu0.1 (libnss-ldap). In general, a standard system upgrade is sufficient to effect the necessary changes. http://www.securityspace.com/smysecure/catid.html?in=USN-152-1 Risk factor : Medium |
| Cross-Ref: |
BugTraq ID: 14126 BugTraq ID: 14125 Common Vulnerability Exposure (CVE) ID: CVE-2005-2069 http://archives.neohapsis.com/archives/fulldisclosure/2005-07/0060.html http://www.openldap.org/its/index.cgi/Incoming?id=3791 http://www.gentoo.org/security/en/glsa/glsa-200507-13.xml http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2005:121 http://www.redhat.com/support/errata/RHSA-2005-751.html http://www.redhat.com/support/errata/RHSA-2005-767.html http://bugzilla.padl.com/show_bug.cgi?id=210 http://bugzilla.padl.com/show_bug.cgi?id=211 http://www.ubuntu.com/usn/usn-152-1 http://www.securityfocus.com/bid/14125 http://www.securityfocus.com/bid/14126 http://www.osvdb.org/17692 http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9445 http://secunia.com/advisories/17233 http://secunia.com/advisories/17845 http://secunia.com/advisories/21520 XForce ISS Database: ldap-tls-information-disclosure(21245) http://xforce.iss.net/xforce/xfdb/21245 |
| Copyright | Copyright (c) 2005 E-Soft Inc. http://www.securityspace.com |
| This is only one of 32582 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |
|