Back

HIGH

security flaw

Published Oct 4, 2006

Description

pam_ldap in nss_ldap on Red Hat Enterprise Linux 4, Fedora Core 3 and earlier, and possibly other distributions does not return an error condition when an LDAP directory server responds with a PasswordPolicyResponse control response, which causes the pam_authenticate function to return a success code even if authentication has failed, as originally reported for xscreensaver.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (25)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Oct 4, 2006
Updated Aug 7, 2024
Reserved Oct 4, 2006
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Sep 20, 2006