CVE Vulnerabilities

CVE-2006-5170

Improper Handling of Exceptional Conditions

Published: Oct 10, 2006 | Modified: Feb 25, 2022
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

pam_ldap in nss_ldap on Red Hat Enterprise Linux 4, Fedora Core 3 and earlier, and possibly other distributions does not return an error condition when an LDAP directory server responds with a PasswordPolicyResponse control response, which causes the pam_authenticate function to return a success code even if authentication has failed, as originally reported for xscreensaver.

Weakness

The product does not handle or incorrectly handles an exceptional condition.

Affected Software

Name Vendor Start Version End Version
Fedora_core Fedoraproject * core_3.0 (including)
Enterprise_linux Redhat 4.0 (including) 4.0 (including)
Libpam-ldap Ubuntu dapper *
Libpam-ldap Ubuntu devel *
Libpam-ldap Ubuntu edgy *
Libpam-ldap Ubuntu feisty *
Red Hat Enterprise Linux 4 RedHat nss_ldap-0:226-17 *

References