pam_ldap and nss_ldap, when used with OpenLDAP and connecting to a slave using TLS, does not use TLS for the subsequent connection if the client is referred to a master, which may cause a password to be sent in cleartext and allows remote attackers to sniff the password.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2005-06-29T04:00:00

Updated: 2024-08-07T22:15:37.352Z

Reserved: 2005-06-29T00:00:00

Link: CVE-2005-2069

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2005-06-30T04:00:00.000

Modified: 2020-11-16T19:30:25.877

Link: CVE-2005-2069

cve-icon Redhat

Severity : Moderate

Publid Date: 2005-06-28T00:00:00Z

Links: CVE-2005-2069 - Bugzilla