Total vulnerabilities in the database
nss-ldapd before 0.6.8 uses world-readable permissions for the /etc/nss-ldapd.conf file, which allows local users to obtain a cleartext password for the LDAP server by reading the bindpw field.
Software | From | Fixed in |
---|---|---|
debian / nss-ldap | - | 0.6.8 |
debian / debian_linux | 5.0 | 5.0.x |