Oval Definition:oval:org.mitre.oval:tst:32018
Comment:openldap-devel is earlier than 0:2.0.27-20
Type:rpminfo_testNamespace:linux
Check_Existence:at_least_one_existsCheck:at least one
State Operator:AND
References
Object:oval:org.mitre.oval:obj:14680
State:oval:org.mitre.oval:ste:10006
Referencing Definitions
Definition IDClassTitleLast Modified
oval:org.mitre.oval:def:9445
V
pam_ldap and nss_ldap, when used with OpenLDAP and connecting to a slave using TLS, does not use TLS for the subsequent connection if the client is referred to a master, which may cause a password to be sent in cleartext and allows remote attackers to sniff the password.
2013-04-29
oval:org.mitre.oval:def:10703
V
OpenLDAP 1.0 through 2.1.19, as used in Apple Mac OS 10.3.4 and 10.3.5 and possibly other operating systems, may allow certain authentication schemes to use hashed (crypt) passwords in the userPassword attribute as if they were plaintext passwords, which allows remote attackers to re-use hashed passwords without decrypting them.
2013-04-29
BACK