CVE-2007-5373
Publication date 11 October 2007
Last updated 24 July 2024
Ubuntu priority
ldapscripts 1.4 and 1.7 sends a password as a command line argument when calling some LDAP programs, which might allow local users to read the password by listing the process and its arguments, as demonstrated by a call to ldappasswd in the _changepassword function.
Status
Package | Ubuntu Release | Status |
---|---|---|
ldapscripts | 9.10 karmic |
Fixed 1.7.1-2
|
9.04 jaunty |
Fixed 1.7.1-2
|
|
8.10 intrepid |
Fixed 1.7.1-2
|
|
8.04 LTS hardy |
Fixed 1.7.1-2
|
|
7.10 gutsy | Ignored end of life, was needed | |
7.04 feisty | Ignored end of life, was needed | |
6.10 edgy | Ignored end of life, was needed | |
6.06 LTS dapper | Ignored end of life |