CVE-2006-5170
published 2006-10-10CVE-2006-5170: pam_ldap in nss_ldap on Red Hat Enterprise Linux 4, Fedora Core 3 and earlier, and possibly other distributions does not return an error condition when an LDAP…
PriorityP335high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
3.83%
88.9th percentile
pam_ldap in nss_ldap on Red Hat Enterprise Linux 4, Fedora Core 3 and earlier, and possibly other distributions does not return an error condition when an LDAP directory server responds with a PasswordPolicyResponse control response, which causes the pam_authenticate function to return a success code even if authentication has failed, as originally reported for xscreensaver.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | libpam-ldap | < libpam-ldap 180-1.2 (bullseye) | libpam-ldap 180-1.2 (bullseye) |
| fedoraproject | fedora_core | <= core_3.0 | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_for_ibm_z_systems | — | — |
| redhat | enterprise_linux_for_ibm_z_systems | — | — |
| redhat | enterprise_linux_for_power_big_endian | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5MEDIUM
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3mcc-2cg8-vvjx: pam_ldap in nss_ldap on Red Hat Enterprise Linux 4, Fedora Core 3 and earlier, and possibly other distributions does not return an error condition whe
ghsa_unreviewed·2022-05-01
CVE-2006-5170 [HIGH] CWE-755 GHSA-3mcc-2cg8-vvjx: pam_ldap in nss_ldap on Red Hat Enterprise Linux 4, Fedora Core 3 and earlier, and possibly other distributions does not return an error condition whe
pam_ldap in nss_ldap on Red Hat Enterprise Linux 4, Fedora Core 3 and earlier, and possibly other distributions does not return an error condition when an LDAP directory server responds with a PasswordPolicyResponse control response, which causes the pam_authenticate function to return a success code even if authentication has failed, as originally reported for xscreensaver.
OSV
CVE-2006-5170: pam_ldap in nss_ldap on Red Hat Enterprise Linux 4, Fedora Core 3 and earlier, and possibly other distributions does not return an error condition whe
osv·2006-10-10·CVSS 7.5
CVE-2006-5170 [HIGH] CVE-2006-5170: pam_ldap in nss_ldap on Red Hat Enterprise Linux 4, Fedora Core 3 and earlier, and possibly other distributions does not return an error condition whe
pam_ldap in nss_ldap on Red Hat Enterprise Linux 4, Fedora Core 3 and earlier, and possibly other distributions does not return an error condition when an LDAP directory server responds with a PasswordPolicyResponse control response, which causes the pam_authenticate function to return a success code even if authentication has failed, as originally reported for xscreensaver.
Red Hat
security flaw
vendor_redhat·2006-09-20·CVSS 7.5
CVE-2006-5170 [HIGH] security flaw
security flaw
pam_ldap in nss_ldap on Red Hat Enterprise Linux 4, Fedora Core 3 and earlier, and possibly other distributions does not return an error condition when an LDAP directory server responds with a PasswordPolicyResponse control response, which causes the pam_authenticate function to return a success code even if authentication has failed, as originally reported for xscreensaver.
Debian
CVE-2006-5170: libpam-ldap - pam_ldap in nss_ldap on Red Hat Enterprise Linux 4, Fedora Core 3 and earlier, a...
vendor_debian·2006·CVSS 7.5
CVE-2006-5170 [HIGH] CVE-2006-5170: libpam-ldap - pam_ldap in nss_ldap on Red Hat Enterprise Linux 4, Fedora Core 3 and earlier, a...
pam_ldap in nss_ldap on Red Hat Enterprise Linux 4, Fedora Core 3 and earlier, and possibly other distributions does not return an error condition when an LDAP directory server responds with a PasswordPolicyResponse control response, which causes the pam_authenticate function to return a success code even if authentication has failed, as originally reported for xscreensaver.
Scope: local
bullseye: resolved (fixed in 180-1.2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2006-5170 security flaw
bugzilla·2018-08-16·CVSS 7.5
CVE-2006-5170 [HIGH] CVE-2006-5170 security flaw
CVE-2006-5170 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
pam_ldap in nss_ldap on Red Hat Enterprise Linux 4, Fedora Core 3 and earlier, and possibly other distributions does not return an error condition when an LDAP directory server responds with a PasswordPolicyResponse control response, which causes the pam_authenticate function to return a success code even if authentication has failed, as originally reported for xscreensaver.
Bugzilla
CVE-2006-5170 When using LDAP for authentication, xscreensaver allows access if account locked out.
bugzilla·2006-10-04·CVSS 7.5
CVE-2006-5170 [HIGH] CVE-2006-5170 When using LDAP for authentication, xscreensaver allows access if account locked out.
CVE-2006-5170 When using LDAP for authentication, xscreensaver allows access if account locked out.
+++ This bug was initially created as a clone of Bug #207286 +++
Description of problem:
We are using Fedora Directory Server for authentication with password policies
configured. When a user's account is locked out, xscreensaver allows access for
that user with *any* password.
Version-Release number of selected component (if applicable):
This has only been noticed in xscreensaver-4.18-5.rhel4.11. We have not tried
any prior versions supplied with RHEL 4.
How reproducible:
Always
Steps to Reproduce:
1. Configure system to authenticate against Fedora Directory Server.
2. Log in as a user and start xscreensaver
3. Lockout the account (in this case, 3 bad passwords causes a lockout)
4.
Bugzilla
CVE-2006-5170 When using LDAP for authentication, xscreensaver allows access if account locked out.
bugzilla·2006-09-20·CVSS 7.5
CVE-2006-5170 [HIGH] CVE-2006-5170 When using LDAP for authentication, xscreensaver allows access if account locked out.
CVE-2006-5170 When using LDAP for authentication, xscreensaver allows access if account locked out.
Description of problem:
We are using Fedora Directory Server for authentication with password policies
configured. When a user's account is locked out, xscreensaver allows access for
that user with *any* password.
Version-Release number of selected component (if applicable):
This has only been noticed in xscreensaver-4.18-5.rhel4.11. We have not tried
any prior versions supplied with RHEL 4.
How reproducible:
Always
Steps to Reproduce:
1. Configure system to authenticate against Fedora Directory Server.
2. Log in as a user and start xscreensaver
3. Lockout the account (in this case, 3 bad passwords causes a lockout)
4. Enter any password into the xscreensaver login prompt
Actual resu
http://bugzilla.padl.com/show_bug.cgi?id=291http://rhn.redhat.com/errata/RHSA-2006-0719.htmlhttp://secunia.com/advisories/22682http://secunia.com/advisories/22685http://secunia.com/advisories/22694http://secunia.com/advisories/22696http://secunia.com/advisories/22869http://secunia.com/advisories/23132http://secunia.com/advisories/23428http://security.gentoo.org/glsa/glsa-200612-19.xmlhttp://securitytracker.com/id?1017153http://www.debian.org/security/2006/dsa-1203http://www.mandriva.com/security/advisories?name=MDKSA-2006:201http://www.novell.com/linux/security/advisories/2006_27_sr.htmlhttp://www.securityfocus.com/archive/1/447859/100/200/threadedhttp://www.securityfocus.com/bid/20880http://www.trustix.org/errata/2006/0061/http://www.vupen.com/english/advisories/2006/4319https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=207286https://issues.rpath.com/browse/RPL-680https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10418http://bugzilla.padl.com/show_bug.cgi?id=291http://rhn.redhat.com/errata/RHSA-2006-0719.htmlhttp://secunia.com/advisories/22682http://secunia.com/advisories/22685http://secunia.com/advisories/22694http://secunia.com/advisories/22696http://secunia.com/advisories/22869http://secunia.com/advisories/23132http://secunia.com/advisories/23428http://security.gentoo.org/glsa/glsa-200612-19.xmlhttp://securitytracker.com/id?1017153http://www.debian.org/security/2006/dsa-1203http://www.mandriva.com/security/advisories?name=MDKSA-2006:201http://www.novell.com/linux/security/advisories/2006_27_sr.htmlhttp://www.securityfocus.com/archive/1/447859/100/200/threadedhttp://www.securityfocus.com/bid/20880http://www.trustix.org/errata/2006/0061/http://www.vupen.com/english/advisories/2006/4319https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=207286https://issues.rpath.com/browse/RPL-680https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10418
2006-10-10
Published