Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

Gentoo: 200507-13 Normal: pam_ldap Plain Text Authentication Leak

gentoo
Calendar Grey July 14, 2005
Scroller Gentoo
Discover the typical risks associated with pam_ldap and nss_ldap password authentication exposures and how to resolve them.
pam_ldap and nss_ldap fail to restart TLS when following a referral, possibly leading to credentials being sent in plain text.

Summary

Gentoo Linux Security Advisory GLSA 200507-13 https://security.gentoo.org/ Severity: Normal Title: pam_ldap and nss_ldap: Plain text authentication leak Date: July 14, 2005 Bugs: #96767 ID: 200507-13

Synopsis ======= pam_ldap and nss_ldap fail to restart TLS when following a referral, possibly leading to credentials being sent in plain text.
Background ========= pam_ldap is a Pluggable Authentication Module which allows authentication against an LDAP directory. nss_ldap is a Name Service Switch module which allows 'passwd', 'group' and 'host' database information to be pulled from LDAP. TLS is Transport Layer Security, a protocol that allows encryption of network communications.
...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround