[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250038

 
 

909

 
 

195843

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-1758-1 nss-ldapd -- insecure config file creation

ID: oval:org.secpod.oval:def:600423Date: (C)2011-05-13   (M)2024-02-19
Class: PATCHFamily: unix




Leigh James that discovered that nss-ldapd, an NSS module for using LDAP as a naming service, by default creates the configuration file /etc/nss-ldapd.conf world-readable which could leak the configured LDAP password if one is used for connecting to the LDAP server. The old stable distribution doesn"t contain nss-ldapd. For the stable distribution this problem has been fixed in version 0.6.7.1. For the unstable distribution this problem has been fixed in version 0.6.8. We recommend that you upgrade your nss-ldapd package.

Platform:
Debian 5.0
Product:
nss-ldapd
Reference:
DSA-1758-1
CVE-2009-1073
CVE    1
CVE-2009-1073
CPE    1
cpe:/o:debian:debian_linux:5.x

© SecPod Technologies