CVE Vulnerabilities

CVE-2006-5170

Improper Handling of Exceptional Conditions

Published: Oct 10, 2006 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

pam_ldap in nss_ldap on Red Hat Enterprise Linux 4, Fedora Core 3 and earlier, and possibly other distributions does not return an error condition when an LDAP directory server responds with a PasswordPolicyResponse control response, which causes the pam_authenticate function to return a success code even if authentication has failed, as originally reported for xscreensaver.

Weakness

The product does not handle or incorrectly handles an exceptional condition.

Affected Software

Name Vendor Start Version End Version
Fedora_core Fedoraproject * core_3.0 (including)
Enterprise_linux Redhat 4.0 (including) 4.0 (including)
Red Hat Enterprise Linux 4 RedHat nss_ldap-0:226-17 *
Libpam-ldap Ubuntu dapper *
Libpam-ldap Ubuntu devel *
Libpam-ldap Ubuntu edgy *
Libpam-ldap Ubuntu feisty *

References