CVE-2007-5794
libnss-ldap - information disclosure
EPSS 1.2%
Description
Race condition in nss_ldap, when used in applications that are linked against the pthread library and fork after a call to nss_ldap, might send user data to the wrong process because of improper handling of the LDAP connection. NOTE: this issue was originally reported for Dovecot with the wrong mailboxes being returned, but other applications might also be affected.
How to fix CVE-2007-5794
To remediate CVE-2007-5794, upgrade the affected package to a fixed version below.
- Debian/libnss-ldap—upgrade to 256-1 or later
- Debian/libnss-ldap—upgrade to 251-7.5etch1 or later
Is CVE-2007-5794 being exploited?
Low — EPSS is 1.2%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 256-1
- from 0, < 251-7.5etch1