Back

MEDIUM

security flaw

Published Jun 29, 2005

Description

pam_ldap and nss_ldap, when used with OpenLDAP and connecting to a slave using TLS, does not use TLS for the subsequent connection if the client is referred to a master, which may cause a password to be sent in cleartext and allows remote attackers to sniff the password.

Affected products

Remediation

Red Hat statement

Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.

Metrics

Weaknesses (1)

References (24)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jun 29, 2005
Updated Aug 7, 2024
Reserved Jun 29, 2005
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Jun 28, 2005