[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2628-1 nss-pam-ldapd -- buffer overflow

ID: oval:org.secpod.oval:def:600971Date: (C)2013-02-19   (M)2023-02-20
Class: PATCHFamily: unix




Garth Mollett discovered that a file descriptor overflow issue in the use of FD_SET in nss-pam-ldapd, which provides NSS and PAM modules for using LDAP as a naming service, can lead to a stack-based buffer overflow. An attacker could, under some circumstances, use this flaw to cause a process that has the NSS or PAM module loaded to crash or potentially execute arbitrary code.

Platform:
Debian 6.0
Product:
libnss-ldapd
Reference:
DSA-2628-1
CVE-2013-0288
CVE    1
CVE-2013-0288
CPE    2
cpe:/a:debian:libnss-ldapd
cpe:/o:debian:debian_linux:6.x

© SecPod Technologies