DEBIAN-CVE-2006-5170

    Dashboard / Vulnerabilities / DEBIAN-CVE-2006-5170

    DEBIAN-CVE-2006-5170

    Published: 10 Oct 2006Last Modified: 27 Aug 2026
    Upstream:

    Summary:

    Details: pam_ldap in nss_ldap on Red Hat Enterprise Linux 4, Fedora Core 3 and earlier, and possibly other distributions does not return an error condition when an LDAP directory server responds with a PasswordPolicyResponse control response, which causes the pam_authenticate function to return a success code even if authentication has failed, as originally reported for xscreensaver.

    Affected packages

    Package

    Name: libpam-ldap

    Purl: pkg:deb/debian/libpam-ldap?arch=source&distro=bullseye

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -180-1.2

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High