Arthur de Jong 'nss-pam-ldapd' Authentication Bypass Vulnerability
BID:46819
Info
Arthur de Jong 'nss-pam-ldapd' Authentication Bypass Vulnerability
| Bugtraq ID: | 46819 |
| Class: | Design Error |
| CVE: |
CVE-2011-0438 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 10 2011 12:00AM |
| Updated: | Mar 19 2015 08:37AM |
| Credit: | Russell Sim |
| Vulnerable: |
Arthur de Jong nss-pam-ldapd 0.8 |
| Not Vulnerable: |
Arthur de Jong nss-pam-ldapd 0.8.1 Arthur de Jong nss-pam-ldapd 0.7.13 |
Discussion
Arthur de Jong 'nss-pam-ldapd' Authentication Bypass Vulnerability
nss-pam-ldapd is prone to an authentication-bypass vulnerability.
Remote attackers can exploit this issue to bypass the authentication mechanism and gain unauthorized access.
nss-pam-ldapd version 0.8.0 is vulnerable.
nss-pam-ldapd is prone to an authentication-bypass vulnerability.
Remote attackers can exploit this issue to bypass the authentication mechanism and gain unauthorized access.
nss-pam-ldapd version 0.8.0 is vulnerable.
Exploit / POC
Arthur de Jong 'nss-pam-ldapd' Authentication Bypass Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Arthur de Jong 'nss-pam-ldapd' Authentication Bypass Vulnerability
Solution:
Updates are available. Please see the references for more details.
Arthurdejong nss-pam-ldapd 0.8
Solution:
Updates are available. Please see the references for more details.
Arthurdejong nss-pam-ldapd 0.8
-
Arthur de Jong nss-pam-ldapd-0.8.0-authentication-bypass-fix.patch
http://arthurdejong.org/nss-pam-ldapd/nss-pam-ldapd-0.8.0-authenticati on-bypass-fix.patch
References
Arthur de Jong 'nss-pam-ldapd' Authentication Bypass Vulnerability
References:
References:
- nss-pam-ldapd Homepage (Arthur de Jong)
- nss-pam-ldapd security advisory (Arthur de Jong)