CVE-2005-2069
libpam-ldap - authentication bypass
EPSS 2.8%
Description
pam_ldap and nss_ldap, when used with OpenLDAP and connecting to a slave using TLS, does not use TLS for the subsequent connection if the client is referred to a master, which may cause a password to be sent in cleartext and allows remote attackers to sniff the password.
How to fix CVE-2005-2069
To remediate CVE-2005-2069, upgrade the affected package to a fixed version below.
- Debian/libnss-ldap—upgrade to 238-1.1 or later
- Debian/libpam-ldap—upgrade to 178-1sarge1 or later
- Debian/libpam-ldap—upgrade to 178-1sarge1 or later
Is CVE-2005-2069 being exploited?
Low — EPSS is 2.8%, meaning exploitation activity has not been observed at scale.
Affected packages (3)
- from 0, < 238-1.1
- from 0, < 178-1sarge1
- from 0, < 178-1sarge1