security flaw
Published Oct 4, 2006
7.5
HIGHCVSS 2.0
EPSS 4.07%
Description
pam_ldap in nss_ldap on Red Hat Enterprise Linux 4, Fedora Core 3 and earlier, and possibly other distributions does not return an error condition when an LDAP directory server responds with a PasswordPolicyResponse control response, which causes the pam_authenticate function to return a success code even if authentication has failed, as originally reported for xscreensaver.
Affected products
No data.
Configuration 1
- ≤ core_3.0
- 4.0
Configuration 2
- 4.0
- 4.0
- 4.0_s390
- 4.0_s390x
- 4.0
- 4.0
- 4.0
Configuration 3
- 3.1
No data.
Red Hat Enterprise Linux 4
nss_ldap-0:226-17
Fixed · RHSA-2006:0719
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 4 | nss_ldap-0:226-17 | Fixed | RHSA-2006:0719 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (16 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 4.07% (0.04070) | 90.36th | v5 (v2026.06.15) |
| Jun 15, 2026 | 3.73% (0.03733) | 88.38th | v5 (v2026.06.15) |
| Oct 1, 2025 | 3.51% (0.03508) | 87.18th | v4 (v2025.03.14) |
| Mar 30, 2025 | 2.28% (0.02281) | 83.21th | v4 (v2025.03.14) |
| Mar 29, 2025 | 4.56% (0.04562) | 81.63th | v4 (v2025.03.14) |
| Mar 17, 2025 | 1.64% (0.01638) | 80.64th | v4 (v2025.03.14) |
| Dec 17, 2024 | 2.71% (0.02715) | 90.20th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.46% (0.00463) | 74.68th | v3 (v2023.03.01) |
| Sep 15, 2023 | 0.46% (0.00463) | 72.47th | v3 (v2023.03.01) |
| Aug 8, 2023 | 0.44% (0.00443) | 71.58th | v3 (v2023.03.01) |
| May 24, 2023 | 0.46% (0.00465) | 71.86th | v3 (v2023.03.01) |
| Mar 8, 2023 | 0.52% (0.00520) | 73.22th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.45% (0.00447) | 71.02th | v3 (v2023.03.01) |
| Mar 6, 2023 | 2.69% (0.02686) | 82.85th | v2 (v2022.01.01) |
| Apr 1, 2022 | 2.69% (0.02686) | 81.17th | v2 (v2022.01.01) |
| Feb 4, 2022 | 2.69% (0.02686) | 62.66th | v2 (v2022.01.01) |
References (25)
- http://bugzilla.padl.com/show_bug.cgi?id=291 x_refsource_CONFIRMBroken LinkIssue TrackingVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2006-0719.html vendor-advisoryx_refsource_REDHATVendor Advisory
- http://secunia.com/advisories/22682 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/22685 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/22694 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/22696 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/22869 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/23132 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/23428 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://security.gentoo.org/glsa/glsa-200612-19.xml vendor-advisoryx_refsource_GENTOOVendor Advisory
- http://securitytracker.com/id?1017153 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- http://www.debian.org/security/2006/dsa-1203 vendor-advisoryx_refsource_DEBIANIssue TrackingPatchVendor Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:201 vendor-advisoryx_refsource_MANDRIVAThird Party Advisory
- http://www.novell.com/linux/security/advisories/2006_27_sr.html vendor-advisoryx_refsource_SUSEBroken LinkVendor Advisory
- http://www.securityfocus.com/archive/1/447859/100/200/threaded mailing-listx_refsource_BUGTRAQThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/20880 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.trustix.org/errata/2006/0061/ vendor-advisoryx_refsource_TRUSTIXBroken LinkThird Party Advisory
- http://www.vupen.com/english/advisories/2006/4319 vdb-entryx_refsource_VUPENThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2006-5170 Vendor Advisory
- https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=207286 x_refsource_CONFIRMIssue TrackingVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1618208 Issue Tracking
- https://issues.rpath.com/browse/RPL-680 x_refsource_CONFIRMBroken LinkThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2006-5170
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10418 vdb-entrysignaturex_refsource_OVALThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2006-5170
| Link | Providers | Tags |
|---|---|---|
| http://bugzilla.padl.com/show_bug.cgi?id=291 | x_refsource_CONFIRMBroken LinkIssue TrackingVendor Advisory | |
| http://rhn.redhat.com/errata/RHSA-2006-0719.html | vendor-advisoryx_refsource_REDHATVendor Advisory | |
| http://secunia.com/advisories/22682 | third-party-advisoryx_refsource_SECUNIAThird Party Advisory | |
| http://secunia.com/advisories/22685 | third-party-advisoryx_refsource_SECUNIAThird Party Advisory | |
| http://secunia.com/advisories/22694 | third-party-advisoryx_refsource_SECUNIAThird Party Advisory | |
| http://secunia.com/advisories/22696 | third-party-advisoryx_refsource_SECUNIAThird Party Advisory | |
| http://secunia.com/advisories/22869 | third-party-advisoryx_refsource_SECUNIAThird Party Advisory | |
| http://secunia.com/advisories/23132 | third-party-advisoryx_refsource_SECUNIAThird Party Advisory | |
| http://secunia.com/advisories/23428 | third-party-advisoryx_refsource_SECUNIAThird Party Advisory | |
| http://security.gentoo.org/glsa/glsa-200612-19.xml | vendor-advisoryx_refsource_GENTOOVendor Advisory | |
| http://securitytracker.com/id?1017153 | vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry | |
| http://www.debian.org/security/2006/dsa-1203 | vendor-advisoryx_refsource_DEBIANIssue TrackingPatchVendor Advisory | |
| http://www.mandriva.com/security/advisories?name=MDKSA-2006:201 | vendor-advisoryx_refsource_MANDRIVAThird Party Advisory | |
| http://www.novell.com/linux/security/advisories/2006_27_sr.html | vendor-advisoryx_refsource_SUSEBroken LinkVendor Advisory | |
| http://www.securityfocus.com/archive/1/447859/100/200/threaded | mailing-listx_refsource_BUGTRAQThird Party AdvisoryVDB Entry | |
| http://www.securityfocus.com/bid/20880 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| http://www.trustix.org/errata/2006/0061/ | vendor-advisoryx_refsource_TRUSTIXBroken LinkThird Party Advisory | |
| http://www.vupen.com/english/advisories/2006/4319 | vdb-entryx_refsource_VUPENThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2006-5170 | Vendor Advisory | |
| https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=207286 | x_refsource_CONFIRMIssue TrackingVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1618208 | Issue Tracking | |
| https://issues.rpath.com/browse/RPL-680 | x_refsource_CONFIRMBroken LinkThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2006-5170 | ||
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10418 | vdb-entrysignaturex_refsource_OVALThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2006-5170 |
Change history (0)
No recorded changes yet.