PADL Software PAM_LDAP TLS Plaintext Password Vulnerability
BID:14126
Info
PADL Software PAM_LDAP TLS Plaintext Password Vulnerability
| Bugtraq ID: | 14126 |
| Class: | Design Error |
| CVE: |
CVE-2005-2069 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 01 2005 12:00AM |
| Updated: | Jul 12 2009 04:06PM |
| Credit: | This issue was reported in a Trustix advisory. |
| Vulnerable: |
Turbolinux Turbolinux Workstation 8.0 Turbolinux Turbolinux Workstation 7.0 Turbolinux Turbolinux Server 10.0 Turbolinux Turbolinux Server 8.0 Turbolinux Turbolinux Server 7.0 Turbolinux Turbolinux Desktop 10.0 Turbolinux Turbolinux 10 F... TurboLinux Personal TurboLinux Multimedia Turbolinux Home Turbolinux Appliance Server Workgroup Edition 1.0 Turbolinux Appliance Server Hosting Edition 1.0 SuSE SUSE Linux Enterprise Server 8 SuSE SUSE Linux Enterprise Server 7 SuSE Linux Openexchange Server SuSE Linux Enterprise Server 9 SuSE Linux Desktop 1.0 SuSE Linux 8.1 SuSE Linux 8.0 i386 SuSE Linux 8.0 SuSE Linux 7.3 sparc SuSE Linux 7.3 ppc SuSE Linux 7.3 i386 SuSE Linux 7.3 SuSE Linux 7.2 i386 SuSE Linux 7.2 SuSE Linux 7.1 x86 SuSE Linux 7.1 sparc SuSE Linux 7.1 ppc SuSE Linux 7.1 alpha SuSE Linux 7.1 SuSE Linux 7.0 sparc SuSE Linux 7.0 ppc SuSE Linux 7.0 i386 SuSE Linux 7.0 alpha SuSE Linux 7.0 SuSE Linux 6.4 ppc SuSE Linux 6.4 i386 SuSE Linux 6.4 alpha SuSE Linux 6.4 SuSE Linux 6.3 ppc SuSE Linux 6.3 alpha SuSE Linux 6.3 SuSE Linux 6.2 SuSE Linux 6.1 alpha SuSE Linux 6.1 SuSE Linux 6.0 SuSE Linux 5.3 SuSE Linux 5.2 SuSE Linux 5.1 SuSE Linux 5.0 SuSE Linux 4.4.1 SuSE Linux 4.4 SuSE Linux 4.3 SuSE Linux 4.2 SuSE Linux 4.0 SuSE Linux 3.0 SuSE Linux 2.0 SuSE Linux 1.0 SGI Advanced Linux Environment 3.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. SuSE Linux Open-Xchange 4.1 S.u.S.E. SuSE eMail Server III S.u.S.E. SuSE eMail Server 3.1 S.u.S.E. SUSE CORE 9 for x86 S.u.S.E. Open-Enterprise-Server 9.0 S.u.S.E. Office Server S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Novell Linux Desktop 1.0 S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 9.1 x86_64 S.u.S.E. Linux Professional 9.1 S.u.S.E. Linux Professional 9.0 x86_64 S.u.S.E. Linux Professional 9.0 S.u.S.E. Linux Professional 8.2 S.u.S.E. Linux Professional 8.2 S.u.S.E. Linux Professional 7.3 S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 S.u.S.E. Linux Personal 8.2 S.u.S.E. Linux Office Server S.u.S.E. Linux IMAP Server 1.0 S.u.S.E. Linux Enterprise Server for S/390 9.0 S.u.S.E. Linux Enterprise Server for S/390 S.u.S.E. Linux Database Server 0 S.u.S.E. LINUX 9.1 Personal Edition CD-ROM Redhat Enterprise Linux WS 4 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux AS 4 Redhat Desktop 4.0 Padl Software pam_ldap Build 169 Padl Software pam_ldap Build 166 Padl Software pam_ldap Build 164 Padl Software pam_ldap Build 148 Padl Software pam_ldap Build 131 Padl Software pam_ldap Build 111 Padl Software nss_ldap Build 85 Padl Software nss_ldap Build 220 Padl Software nss_ldap Build 211 Padl Software nss_ldap Build 202 Padl Software nss_ldap Build 199 Padl Software nss_ldap Build 198 Padl Software nss_ldap Build 194 Padl Software nss_ldap Build 192 Padl Software nss_ldap Build 191 Padl Software nss_ldap Build 190 Padl Software nss_ldap Build 189 Padl Software nss_ldap Build 188 Padl Software nss_ldap Build 187 Padl Software nss_ldap Build 186 Padl Software nss_ldap Build 185.3 Padl Software nss_ldap Build 185.2 Padl Software nss_ldap Build 185.1 Padl Software nss_ldap Build 185 Padl Software nss_ldap Build 184 Padl Software nss_ldap Build 183 Padl Software nss_ldap Build 181 Padl Software nss_ldap Build 180 Padl Software nss_ldap Build 173 Padl Software nss_ldap Build 172 Padl Software nss_ldap Build 122 Padl Software nss_ldap Build 121 Padl Software nss_ldap Build 113 Padl Software nss_ldap Build 107 Padl Software nss_ldap Build 105 Mandriva Linux Mandrake 10.2 x86_64 Mandriva Linux Mandrake 10.2 Mandriva Linux Mandrake 10.1 x86_64 Mandriva Linux Mandrake 10.1 Mandriva Linux Mandrake 10.0 AMD64 Mandriva Linux Mandrake 10.0 MandrakeSoft Multi Network Firewall 2.0 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 MandrakeSoft Corporate Server 2.1 x86_64 MandrakeSoft Corporate Server 2.1 Gentoo Linux |
| Not Vulnerable: | |
Discussion
PADL Software PAM_LDAP TLS Plaintext Password Vulnerability
PAM_LDAP is affected by a password disclosure vulnerability when used with TLS.
This issue arises when a connection to a slave is established using TLS and the client is referred to a master. TLS is not used with this connection, which can allow an attacker to sniff network traffic and obtain user credentials.
PAM_LDAP build 166 is known to be vulnerable at the moment. Other versions may be affected as well.
PAM_LDAP is affected by a password disclosure vulnerability when used with TLS.
This issue arises when a connection to a slave is established using TLS and the client is referred to a master. TLS is not used with this connection, which can allow an attacker to sniff network traffic and obtain user credentials.
PAM_LDAP build 166 is known to be vulnerable at the moment. Other versions may be affected as well.
Exploit / POC
PADL Software PAM_LDAP TLS Plaintext Password Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
PADL Software PAM_LDAP TLS Plaintext Password Vulnerability
Solution:
Trustix has released advisory TSLSA-2005-0031 to address various issues. Please see the referenced advisory for more information.
Gentoo has released advisory GLSA 200507-13 to address this issue. Please see the referenced advisory for more information. Gentoo users may carry out the following commands to update their computers:
All pam_ldap users:
emerge --sync
emerge --ask --oneshot --verbose ">=sys-auth/pam_ldap-178-r1"
All nss_ldap users:
emerge --sync
emerge --ask --oneshot --verbose sys-auth/nss_ldap
Mandriva had released security advisory MDKSA-2005:121 addressing this issue. Please see the referenced advisory for further information.
Ubuntu Linux has released security advisory USN-152-1 addressing this issue. Please see the referenced advisory for details on obtaining and applying the appropriate updates.
Turbolinux has released advisories TLSA-2005-86 and TLSA-2005-87 to address this issue in nss_ldap and pam_ldap, respectively. Please see the referenced advisories for further information.
SUSE has released a security summary report (SUSE-SR:2005:020) addressing this and other issues. Please see the referenced advisory for further information.
Conectiva Linux has released security advisory CLSA-2005:1027 addressing this issue. Please see the referenced advisory for details on obtaining and applying the appropriate updates.
RedHat has released advisory RHSA-2005:767-8, along with fixes to address this issue in RedHat Enterprise operating systems. Please see the referenced advisory for further information.
SGI has released advisory 20051003-01-U and fixes for this and other issues. Please see the referenced advisory for further details.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Padl Software pam_ldap Build 111
Padl Software pam_ldap Build 164
Padl Software pam_ldap Build 148
Solution:
Trustix has released advisory TSLSA-2005-0031 to address various issues. Please see the referenced advisory for more information.
Gentoo has released advisory GLSA 200507-13 to address this issue. Please see the referenced advisory for more information. Gentoo users may carry out the following commands to update their computers:
All pam_ldap users:
emerge --sync
emerge --ask --oneshot --verbose ">=sys-auth/pam_ldap-178-r1"
All nss_ldap users:
emerge --sync
emerge --ask --oneshot --verbose sys-auth/nss_ldap
Mandriva had released security advisory MDKSA-2005:121 addressing this issue. Please see the referenced advisory for further information.
Ubuntu Linux has released security advisory USN-152-1 addressing this issue. Please see the referenced advisory for details on obtaining and applying the appropriate updates.
Turbolinux has released advisories TLSA-2005-86 and TLSA-2005-87 to address this issue in nss_ldap and pam_ldap, respectively. Please see the referenced advisories for further information.
SUSE has released a security summary report (SUSE-SR:2005:020) addressing this and other issues. Please see the referenced advisory for further information.
Conectiva Linux has released security advisory CLSA-2005:1027 addressing this issue. Please see the referenced advisory for details on obtaining and applying the appropriate updates.
RedHat has released advisory RHSA-2005:767-8, along with fixes to address this issue in RedHat Enterprise operating systems. Please see the referenced advisory for further information.
SGI has released advisory 20051003-01-U and fixes for this and other issues. Please see the referenced advisory for further details.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Padl Software pam_ldap Build 111
-
Turbolinux pam_ldap-148-3.i586.rpm
Turbolinux 7 Workstation
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Workstation/ 7/updates/RPMS/pam_ldap-148-3.i586.rpm
Padl Software pam_ldap Build 164
-
Turbolinux pam_ldap-164-2.i586.rpm
Turbolinux 10 Desktop, Turbolinux 10 F..., Turbolinux Home, Turbolinux Multimedia, Turbolinux Personal
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Desktop/10/u pdates/RPMS/pam_ldap-164-2.i586.rpm -
Turbolinux pam_ldap-164-2.i586.rpm
Turbolinux 10 Server
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Server/10/up dates/RPMS/pam_ldap-164-2.i586.rpm
Padl Software pam_ldap Build 148
-
Turbolinux pam_ldap-148-3.i586.rpm
Turbolinux 8 Server
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Server/8/upd ates/RPMS/pam_ldap-148-3.i586.rpm
References
PADL Software PAM_LDAP TLS Plaintext Password Vulnerability
References:
References:
- pam_ldap Product Page (Padl Software)
- RHSA-2005:767-8 - openldap and nss_ldap security update (RedHat)