PADL Software PAM_LDAP Authentication Bypass Vulnerability
BID:14649
Info
PADL Software PAM_LDAP Authentication Bypass Vulnerability
| Bugtraq ID: | 14649 |
| Class: | Design Error |
| CVE: |
CVE-2005-2641 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 24 2005 12:00AM |
| Updated: | Oct 06 2006 06:35PM |
| Credit: | Announced by the vendor. |
| Vulnerable: |
SGI Advanced Linux Environment 3.0 rPath rPath Linux 1 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux AS 4 Redhat Desktop 4.0 Padl Software pam_ldap Build 179 Padl Software pam_ldap Build 169 Mandriva Linux Mandrake 10.2 x86_64 Mandriva Linux Mandrake 10.2 Mandriva Linux Mandrake 10.1 x86_64 Mandriva Linux Mandrake 10.1 Gentoo Linux |
| Not Vulnerable: |
Padl Software pam_ldap Build 180 |
Discussion
PADL Software PAM_LDAP Authentication Bypass Vulnerability
PAM_LDAP is prone to an authentication-bypass vulnerability when handling new password policy control. This could allow an unauthorized user to bypass authentication.
This vulnerability was reported to affect PAM_LDAP builds 169 through 179.
PAM_LDAP is prone to an authentication-bypass vulnerability when handling new password policy control. This could allow an unauthorized user to bypass authentication.
This vulnerability was reported to affect PAM_LDAP builds 169 through 179.
Exploit / POC
PADL Software PAM_LDAP Authentication Bypass Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
PADL Software PAM_LDAP Authentication Bypass Vulnerability
Solution:
This issue has been addressed in Build 180 of PAM_LDAP.
Please see the referenced advisories for more information.
Padl Software pam_ldap Build 169
Padl Software pam_ldap Build 179
Solution:
This issue has been addressed in Build 180 of PAM_LDAP.
Please see the referenced advisories for more information.
Padl Software pam_ldap Build 169
-
Padl Software pam_ldap Build 180
ftp://ftp.padl.com/pub/pam_ldap.tgz
Padl Software pam_ldap Build 179
-
Padl Software pam_ldap Build 180
ftp://ftp.padl.com/pub/pam_ldap.tgz
References
PADL Software PAM_LDAP Authentication Bypass Vulnerability
References:
References:
- pam_ldap Product Page (Padl Software)
- RHSA-2005:767-8 - openldap and nss_ldap security update (RedHat)