Total vulnerabilities in the database
pam_ldap in nss_ldap on Red Hat Enterprise Linux 4, Fedora Core 3 and earlier, and possibly other distributions does not return an error condition when an LDAP directory server responds with a PasswordPolicyResponse control response, which causes the pam_authenticate function to return a success code even if authentication has failed, as originally reported for xscreensaver.
Software | From | Fixed in |
---|---|---|
redhat / enterprise_linux | 4.0 | 4.0.x |
fedoraproject / fedora_core | - | core_3.0.x |
redhat / enterprise_linux_desktop | 4.0 | 4.0.x |
redhat / enterprise_linux_server | 4.0 | 4.0.x |
redhat / enterprise_linux_workstation | 4.0 | 4.0.x |
redhat / enterprise_linux_for_ibm_z_systems | 4.0_s390x | 4.0_s390x.x |
redhat / enterprise_linux_for_ibm_z_systems | 4.0_s390 | 4.0_s390.x |
redhat / enterprise_linux_for_power_big_endian | 4.0 | 4.0.x |
debian / debian_linux | 3.1 | 3.1.x |