Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.57565
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-1203-1)
Summary:The remote host is missing an update for the Debian 'libpam-ldap' package(s) announced via the DSA-1203-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'libpam-ldap' package(s) announced via the DSA-1203-1 advisory.

Vulnerability Insight:
Steve Rigler discovered that the PAM module for authentication against LDAP servers processes PasswordPolicyReponse control messages incorrectly, which might lead to an attacker being able to login into a suspended system account.

For the stable distribution (sarge) this problem has been fixed in version 178-1sarge3. Due to technical problems with the security buildd infrastructure this update lacks a build for the Sun Sparc architecture. It will be released as soon as the problems are resolved.

For the unstable distribution (sid) this problem has been fixed in version 180-1.2.

We recommend that you upgrade your libpam-ldap package.

Affected Software/OS:
'libpam-ldap' package(s) on Debian 3.1.

Solution:
Please install the updated package(s).

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2006-5170
1017153
http://securitytracker.com/id?1017153
2006-0061
http://www.trustix.org/errata/2006/0061/
20061005 rPSA-2006-0183-1 nss_ldap
http://www.securityfocus.com/archive/1/447859/100/200/threaded
20880
http://www.securityfocus.com/bid/20880
22682
http://secunia.com/advisories/22682
22685
http://secunia.com/advisories/22685
22694
http://secunia.com/advisories/22694
22696
http://secunia.com/advisories/22696
22869
http://secunia.com/advisories/22869
23132
http://secunia.com/advisories/23132
23428
http://secunia.com/advisories/23428
ADV-2006-4319
http://www.vupen.com/english/advisories/2006/4319
DSA-1203
http://www.debian.org/security/2006/dsa-1203
GLSA-200612-19
http://security.gentoo.org/glsa/glsa-200612-19.xml
MDKSA-2006:201
http://www.mandriva.com/security/advisories?name=MDKSA-2006:201
RHSA-2006:0719
http://rhn.redhat.com/errata/RHSA-2006-0719.html
SUSE-SR:2006:027
http://www.novell.com/linux/security/advisories/2006_27_sr.html
http://bugzilla.padl.com/show_bug.cgi?id=291
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=207286
https://issues.rpath.com/browse/RPL-680
oval:org.mitre.oval:def:10418
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10418
CopyrightCopyright (C) 2008 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.