Oval Definition:oval:org.mitre.oval:tst:32089
Comment:openldap-devel is earlier than 0:2.2.13-4
Type:rpminfo_testNamespace:linux
Check_Existence:at_least_one_existsCheck:at least one
State Operator:AND
References
Object:oval:org.mitre.oval:obj:14680
State:oval:org.mitre.oval:ste:9767
Referencing Definitions
Definition IDClassTitleLast Modified
oval:org.mitre.oval:def:9445
V
pam_ldap and nss_ldap, when used with OpenLDAP and connecting to a slave using TLS, does not use TLS for the subsequent connection if the client is referred to a master, which may cause a password to be sent in cleartext and allows remote attackers to sniff the password.
2013-04-29
oval:org.mitre.oval:def:10370
V
Unknown vulnerability in pam_ldap before 180 does not properly handle a new password policy control, which could allow attackers to gain privileges. NOTE: CVE-2005-2497 had also been assigned to this issue, but CVE-2005-2641 is the correct candidate.
2013-04-29
BACK