nss-ldapd before 0.6.8 uses world-readable permissions for the /etc/nss-ldapd.conf file, which allows local users to obtain a cleartext password for the LDAP server by reading the bindpw field.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2009-03-31 11:24
Updated : 2009-04-07 22:36
NVD link : CVE-2009-1073
Mitre link : CVE-2009-1073
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
debian
- nss-ldap