VDB
CVE-2006-5170
CVE-2006-5170
PUBLISHED
CVSS 7.5 HIGH
pam_ldap in nss_ldap on Red Hat Enterprise Linux 4, Fedora Core 3 and earlier, and possibly other distributions does not return an error condition when an LDAP directory server responds with a PasswordPolicyResponse control response, which causes the pam_authenticate function to return a success code even if authentication has failed, as originally reported for xscreensaver.
EPSS 4.35% · 89.1th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
4.35%
89.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| redhat | enterprise_linux_for_ibm_z_systems | 4.0_s390, * |
| redhat | enterprise_linux_server | 4.0 |
| redhat | enterprise_linux_desktop | 4.0 |
| debian | debian_linux | 3.1 |
| redhat | enterprise_linux_workstation | 4.0 |
| fedoraproject | fedora_core | 0 |
| redhat | enterprise_linux | 4.0, 4.0 |
| n/a | n/a | * |
| redhat | enterprise_linux_for_power_big_endian | 4.0 |
Timeline
- Oct 4, 2006 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
- Dec 22, 2023 EPSS Score
References
- 1017153 vdb
- RHSA-2006:0719 vendor-advisory
- https://issues.rpath.com/browse/RPL-680 url
- 22682 third-party-advisory
- 20061005 rPSA-2006-0183-1 nss_ldap mailing-list
- 2006-0061 vendor-advisory
- 20880 vdb
- 22685 third-party-advisory
- MDKSA-2006:201 vendor-advisory
- SUSE-SR:2006:027 vendor-advisory
- 22869 third-party-advisory
- 22694 third-party-advisory
- 23132 third-party-advisory
- GLSA-200612-19 vendor-advisory
- 23428 third-party-advisory
- oval:org.mitre.oval:def:10418 vdb
- DSA-1203 vendor-advisory
- http://bugzilla.padl.com/show_bug.cgi?id=291 url
- https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=207286 url
- 22696 third-party-advisory
…and 3 more