CVE-2005-2069
published 2005-06-30CVE-2005-2069: pam_ldap and nss_ldap, when used with OpenLDAP and connecting to a slave using TLS, does not use TLS for the subsequent connection if the client is referred to…
PriorityP426medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
2.75%
84.6th percentile
pam_ldap and nss_ldap, when used with OpenLDAP and connecting to a slave using TLS, does not use TLS for the subsequent connection if the client is referred to a master, which may cause a password to be sent in cleartext and allows remote attackers to sniff the password.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libnss-ldap | < libnss-ldap 238-1.1 (bullseye) | libnss-ldap 238-1.1 (bullseye) |
| debian | libpam-ldap | < libnss-ldap 238-1.1 (bullseye) | libnss-ldap 238-1.1 (bullseye) |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_msrc5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
CVE-2005-2069: NIST NVD Details: https://nvd
vendor_msrc·2020-09-08·CVSS 5.0
CVE-2005-2069 [MEDIUM] CVE-2005-2069: NIST NVD Details: https://nvd
NIST NVD Details: https://nvd.nist.gov/vuln/detail/CVE-2005-2069
Mariner: Mariner
[email protected]: [email protected]
Exploit Status: DOS:N/A
Remediation: openldap
Ubuntu
PAM/NSS LDAP vulnerabilitiy
vendor_ubuntu·2005-07-21
CVE-2005-2069 PAM/NSS LDAP vulnerabilitiy
Title: PAM/NSS LDAP vulnerabilitiy
Summary: PAM/NSS LDAP vulnerabilitiy
Andrea Barisani discovered a flaw in the SSL handling of pam-ldap and
libnss-ldap. When a client connected to a consumer LDAP server using SSL,
the consumer server did not use SSL as well when contacting the LDAP
provider server. This caused passwords and other confident information
to be transmitted unencrypted between the consumer and the provider.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
security flaw
vendor_redhat·2005-06-28·CVSS 5.0
CVE-2005-2069 [MEDIUM] security flaw
security flaw
pam_ldap and nss_ldap, when used with OpenLDAP and connecting to a slave using TLS, does not use TLS for the subsequent connection if the client is referred to a master, which may cause a password to be sent in cleartext and allows remote attackers to sniff the password.
Statement: Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.
Debian
CVE-2005-2069: libnss-ldap - pam_ldap and nss_ldap, when used with OpenLDAP and connecting to a slave using T...
vendor_debian·2005·CVSS 5.0
CVE-2005-2069 [MEDIUM] CVE-2005-2069: libnss-ldap - pam_ldap and nss_ldap, when used with OpenLDAP and connecting to a slave using T...
pam_ldap and nss_ldap, when used with OpenLDAP and connecting to a slave using TLS, does not use TLS for the subsequent connection if the client is referred to a master, which may cause a password to be sent in cleartext and allows remote attackers to sniff the password.
Scope: local
bullseye: resolved (fixed in 238-1.1)
GHSA
GHSA-fv7v-76vm-38q4: pam_ldap and nss_ldap, when used with OpenLDAP and connecting to a slave using TLS, does not use TLS for the subsequent connection if the client is re
ghsa_unreviewed·2022-05-01
CVE-2005-2069 [MEDIUM] CWE-319 GHSA-fv7v-76vm-38q4: pam_ldap and nss_ldap, when used with OpenLDAP and connecting to a slave using TLS, does not use TLS for the subsequent connection if the client is re
pam_ldap and nss_ldap, when used with OpenLDAP and connecting to a slave using TLS, does not use TLS for the subsequent connection if the client is referred to a master, which may cause a password to be sent in cleartext and allows remote attackers to sniff the password.
OSV
CVE-2005-2069: pam_ldap and nss_ldap, when used with OpenLDAP and connecting to a slave using TLS, does not use TLS for the subsequent connection if the client is re
osv·2005-06-30·CVSS 5.0
CVE-2005-2069 [MEDIUM] CVE-2005-2069: pam_ldap and nss_ldap, when used with OpenLDAP and connecting to a slave using TLS, does not use TLS for the subsequent connection if the client is re
pam_ldap and nss_ldap, when used with OpenLDAP and connecting to a slave using TLS, does not use TLS for the subsequent connection if the client is referred to a master, which may cause a password to be sent in cleartext and allows remote attackers to sniff the password.
No detection rules found.
No public exploits indexed.
http://archives.neohapsis.com/archives/fulldisclosure/2005-07/0060.htmlhttp://bugs.gentoo.org/show_bug.cgi?id=96767http://bugzilla.padl.com/show_bug.cgi?id=210http://bugzilla.padl.com/show_bug.cgi?id=211http://secunia.com/advisories/17233http://secunia.com/advisories/17845http://secunia.com/advisories/21520http://support.avaya.com/elmodocs2/security/ASA-2006-157.htmhttp://www.gentoo.org/security/en/glsa/glsa-200507-13.xmlhttp://www.openldap.org/its/index.cgi/Incoming?id=3791http://www.osvdb.org/17692http://www.redhat.com/support/errata/RHSA-2005-751.htmlhttp://www.redhat.com/support/errata/RHSA-2005-767.htmlhttp://www.securityfocus.com/bid/14125http://www.securityfocus.com/bid/14126http://www.ubuntu.com/usn/usn-152-1http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2005:121https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=161990https://exchange.xforce.ibmcloud.com/vulnerabilities/21245https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9445http://archives.neohapsis.com/archives/fulldisclosure/2005-07/0060.htmlhttp://bugs.gentoo.org/show_bug.cgi?id=96767http://bugzilla.padl.com/show_bug.cgi?id=210http://bugzilla.padl.com/show_bug.cgi?id=211http://secunia.com/advisories/17233http://secunia.com/advisories/17845http://secunia.com/advisories/21520http://support.avaya.com/elmodocs2/security/ASA-2006-157.htmhttp://www.gentoo.org/security/en/glsa/glsa-200507-13.xmlhttp://www.openldap.org/its/index.cgi/Incoming?id=3791http://www.osvdb.org/17692http://www.redhat.com/support/errata/RHSA-2005-751.htmlhttp://www.redhat.com/support/errata/RHSA-2005-767.htmlhttp://www.securityfocus.com/bid/14125http://www.securityfocus.com/bid/14126http://www.ubuntu.com/usn/usn-152-1http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2005:121https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=161990https://exchange.xforce.ibmcloud.com/vulnerabilities/21245https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9445
2005-06-30
Published