DEBIAN-CVE-2005-2641

    Dashboard / Vulnerabilities / DEBIAN-CVE-2005-2641

    DEBIAN-CVE-2005-2641

    Published: 23 Aug 2005Last Modified: 1 Sept 2026
    Upstream:

    Summary:

    Details: Unknown vulnerability in pam_ldap before 180 does not properly handle a new password policy control, which could allow attackers to gain privileges. NOTE: CVE-2005-2497 had also been assigned to this issue, but CVE-2005-2641 is the correct candidate.

    Affected packages

    Package

    Name: libpam-ldap

    Purl: pkg:deb/debian/libpam-ldap?arch=source&distro=bullseye

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -178-1sarge1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High