CVE-2007-5373

Publication date 11 October 2007

Last updated 24 July 2024


Ubuntu priority

ldapscripts 1.4 and 1.7 sends a password as a command line argument when calling some LDAP programs, which might allow local users to read the password by listing the process and its arguments, as demonstrated by a call to ldappasswd in the _changepassword function.

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
ldapscripts 9.10 karmic
Fixed 1.7.1-2
9.04 jaunty
Fixed 1.7.1-2
8.10 intrepid
Fixed 1.7.1-2
8.04 LTS hardy
Fixed 1.7.1-2
7.10 gutsy Ignored end of life, was needed
7.04 feisty Ignored end of life, was needed
6.10 edgy Ignored end of life, was needed
6.06 LTS dapper Ignored end of life