Oval Definition:oval:com.redhat.rhsa:def:20060719
Revision Date:2006-11-15Version:638
Title:RHSA-2006:0719: nss_ldap security update (Moderate)
Description:nss_ldap is a set of C library extensions that allow X.500 and LDAP directory servers to be used as primary sources for aliases, ethers, groups, hosts, networks, protocols, users, RPCs, services, and shadow passwords.

  • A flaw was found in the way nss_ldap handled a PasswordPolicyResponse control sent by an LDAP server. If an LDAP server responded to an authentication request with a PasswordPolicyResponse control, it was possible for an application using nss_ldap to improperly authenticate certain users. (CVE-2006-5170)

    This flaw was only exploitable within applications which did not properly process nss_ldap error messages. Only xscreensaver is currently known to exhibit this behavior.

    All users of nss_ldap should upgrade to these updated packages, which contain a backported patch that resolves this issue.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2006-5170
    RHSA-2006:0719
    RHSA-2006:0719-01
    RHSA-2006:0719-01
    Platform(s):Red Hat Enterprise Linux 4
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND nss_ldap is earlier than 0:226-17
  • AND nss_ldap is signed with Red Hat redhatrelease2 key
  • BACK