CVE-2011-0438
Published: 15 March 2011
nslcd/pam.c in the nss-pam-ldapd 0.8.0 PAM module returns a success code when a user is not found in LDAP, which allows remote attackers to bypass authentication.
Priority
Status
Package | Release | Status |
---|---|---|
nss-pam-ldapd Launchpad, Ubuntu, Debian |
dapper |
Does not exist
|
hardy |
Does not exist
|
|
karmic |
Does not exist
|
|
lucid |
Not vulnerable
(0.8.0 only)
|
|
maverick |
Not vulnerable
(0.8.0 only)
|
|
upstream |
Released
(0.8.1)
|