CVE-2006-5170
libpam-ldap
EPSS 3.8%
描述
pam_ldap in nss_ldap on Red Hat Enterprise Linux 4, Fedora Core 3 and earlier, and possibly other distributions does not return an error condition when an LDAP directory server responds with a PasswordPolicyResponse control response, which causes the pam_authenticate function to return a success code even if authentication has failed, as originally reported for xscreensaver.
如何修補 CVE-2006-5170
要修補 CVE-2006-5170,請將受影響套件升級到下列已修補版本。
- Debian/libpam-ldap—升級至 180-1.2 或更新版本
- Debian/libpam-ldap—升級至 178-1sarge3 或更新版本
CVE-2006-5170 正在被利用嗎?
低 — EPSS 為 3.8%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 180-1.2
- from 0, < 178-1sarge3