Vulnerability Name:

CVE-2006-5170 (CCN-30084)

Assigned:2006-09-20
Published:2006-09-20
Updated:2022-02-25
Summary:pam_ldap in nss_ldap on Red Hat Enterprise Linux 4, Fedora Core 3 and earlier, and possibly other distributions does not return an error condition when an LDAP directory server responds with a PasswordPolicyResponse control response, which causes the pam_authenticate function to return a success code even if authentication has failed, as originally reported for xscreensaver.
CVSS v3 Severity:5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): High
Availibility (A): None
CVSS v2 Severity:7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
5.4 Medium (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:C/A:N)
4.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:C/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Complete
Availibility (A): None
Vulnerability Type:CWE-755
Vulnerability Consequences:Bypass Security
References:Source: CCN
Type: PADL Bugzilla Bug 291
shouldn't suppress errors which don't need to be suppressed

Source: CONFIRM
Type: Broken Link, Issue Tracking, Vendor Advisory
http://bugzilla.padl.com/show_bug.cgi?id=291

Source: MITRE
Type: CNA
CVE-2006-5170

Source: CCN
Type: RHSA-2006-0719
Moderate: nss_ldap security update

Source: REDHAT
Type: Vendor Advisory
RHSA-2006:0719

Source: CCN
Type: SA22682
pam_ldap "PasswordPolicyResponse" Security Bypass

Source: SECUNIA
Type: Third Party Advisory
22682

Source: SECUNIA
Type: Third Party Advisory
22685

Source: SECUNIA
Type: Third Party Advisory
22694

Source: SECUNIA
Type: Third Party Advisory
22696

Source: SECUNIA
Type: Third Party Advisory
22869

Source: SECUNIA
Type: Third Party Advisory
23132

Source: SECUNIA
Type: Third Party Advisory
23428

Source: GENTOO
Type: Vendor Advisory
GLSA-200612-19

Source: CCN
Type: SECTRACK ID: 1017153
nss_ldap Error in pam_ldap in Processing PasswordPolicyReponse Messages May Let Remote Users Bypass Authentication

Source: SECTRACK
Type: Third Party Advisory, VDB Entry
1017153

Source: CCN
Type: ASA-2007-010
nss_ldap security update (RHSA-2006-0719)

Source: DEBIAN
Type: Issue Tracking, Patch, Vendor Advisory
DSA-1203

Source: DEBIAN
Type: DSA-1203
libpam-ldap -- programming error

Source: CCN
Type: GLSA-200612-19
pam_ldap: Authentication bypass vulnerability

Source: MANDRIVA
Type: Third Party Advisory
MDKSA-2006:201

Source: SUSE
Type: Broken Link, Vendor Advisory
SUSE-SR:2006:027

Source: CCN
Type: PADL Software Pty Ltd Web site
pam_ldap

Source: BUGTRAQ
Type: Third Party Advisory, VDB Entry
20061005 rPSA-2006-0183-1 nss_ldap

Source: BID
Type: Third Party Advisory, VDB Entry
20880

Source: CCN
Type: BID-20880
PADL Software Pam_Ldap PasswordPolicyResponse Authentication Bypass Vulnerability

Source: TRUSTIX
Type: Broken Link, Third Party Advisory
2006-0061

Source: VUPEN
Type: Third Party Advisory
ADV-2006-4319

Source: CCN
Type: Red Hat Bugzilla Bug 207286
CVE-2006-5170 When using LDAP for authentication, xscreensaver allows access if account locked out.

Source: CONFIRM
Type: Issue Tracking, Vendor Advisory
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=207286

Source: XF
Type: UNKNOWN
pamldap-passwordpolicy-security-bypass(30084)

Source: CCN
Type: RPL-680
pam_ldap module in nss_ldap handles locked accounts incorrectly CVE-2006-5170

Source: CONFIRM
Type: Broken Link, Third Party Advisory
https://issues.rpath.com/browse/RPL-680

Source: OVAL
Type: Third Party Advisory
oval:org.mitre.oval:def:10418

Source: SUSE
Type: SUSE-SR:2006:027
SUSE Security Summary Report

Vulnerable Configuration:Configuration 1:
  • cpe:/o:redhat:enterprise_linux:4.0:*:linux_kernel_2.6.9:*:*:*:*:*
  • OR cpe:/o:fedoraproject:fedora_core:*:*:*:*:*:*:*:* (Version <= core_3.0)

  • Configuration 2:
  • cpe:/o:redhat:enterprise_linux:4.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_desktop:4.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_for_ibm_z_systems:4.0_s390:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_for_ibm_z_systems:4.0_s390x:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_for_power_big_endian:4.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_server:4.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_workstation:4.0:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/o:debian:debian_linux:3.1:*:*:*:*:*:*:*

  • Configuration RedHat 1:
  • cpe:/o:redhat:enterprise_linux:4:*:*:*:*:*:*:*

  • Configuration RedHat 2:
  • cpe:/o:redhat:enterprise_linux:4::as:*:*:*:*:*

  • Configuration RedHat 3:
  • cpe:/o:redhat:enterprise_linux:4::desktop:*:*:*:*:*

  • Configuration RedHat 4:
  • cpe:/o:redhat:enterprise_linux:4::es:*:*:*:*:*

  • Configuration RedHat 5:
  • cpe:/o:redhat:enterprise_linux:4::ws:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:42415
    P
    Security update for systemd-presets-common-SUSE (Moderate) (in QA)
    2022-07-13
    oval:org.opensuse.security:def:20065170
    V
    CVE-2006-5170
    2022-05-20
    oval:org.opensuse.security:def:42206
    P
    Security update for containerd (Moderate)
    2022-03-04
    oval:org.opensuse.security:def:26187
    P
    Security update for libvpx (Moderate)
    2021-12-23
    oval:org.opensuse.security:def:32250
    P
    Security update for log4j (Important)
    2021-12-17
    oval:org.opensuse.security:def:31720
    P
    Security update for xorg-x11-server (Important)
    2021-12-14
    oval:org.opensuse.security:def:32228
    P
    Security update for java-1_7_0-openjdk (Important)
    2021-11-24
    oval:org.opensuse.security:def:31311
    P
    Security update for java-1_8_0-openjdk (Important)
    2021-11-23
    oval:org.opensuse.security:def:31703
    P
    Security update for MozillaFirefox (Important)
    2021-11-17
    oval:org.opensuse.security:def:26151
    P
    Security update for python3 (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:31278
    P
    Security update for xen (Important)
    2021-09-23
    oval:org.opensuse.security:def:32189
    P
    Security update for the Linux Kernel (Live Patch 39 for SLE 12 SP3) (Important)
    2021-09-23
    oval:org.opensuse.security:def:26134
    P
    Security update for the Linux Kernel (Important)
    2021-09-23
    oval:org.opensuse.security:def:31266
    P
    Security update for transfig (Moderate)
    2021-09-16
    oval:org.opensuse.security:def:31267
    P
    Security update for gtk-vnc (Moderate)
    2021-09-16
    oval:org.opensuse.security:def:26125
    P
    Security update for grilo (Important)
    2021-09-09
    oval:org.opensuse.security:def:32180
    P
    Security update for file (Important)
    2021-09-02
    oval:org.opensuse.security:def:32971
    P
    Security update for dbus-1 (Important)
    2021-08-02
    oval:org.opensuse.security:def:26094
    P
    Security update for curl (Moderate)
    2021-07-23
    oval:org.opensuse.security:def:32140
    P
    Security update for MozillaFirefox (Important)
    2021-07-16
    oval:org.opensuse.security:def:26081
    P
    Security update for libgcrypt (Important)
    2021-06-24
    oval:org.opensuse.security:def:36260
    P
    pam_ldap-184-147.20 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:31633
    P
    Security update for libX11 (Important)
    2021-06-08
    oval:org.opensuse.security:def:42667
    P
    pam_ldap-184-147.20 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:26067
    P
    Security update for MozillaFirefox (Important)
    2021-06-08
    oval:org.opensuse.security:def:32932
    P
    Security update for dhcp (Important)
    2021-06-01
    oval:org.opensuse.security:def:32093
    P
    Security update for djvulibre (Important)
    2021-05-19
    oval:org.opensuse.security:def:32086
    P
    Security update for java-1_7_0-openjdk (Moderate)
    2021-04-29
    oval:org.opensuse.security:def:32084
    P
    Security update for gdm (Important)
    2021-04-28
    oval:org.opensuse.security:def:26028
    P
    Security update for xorg-x11-server (Important)
    2021-04-13
    oval:org.opensuse.security:def:31352
    P
    Security update for openldap2 (Important)
    2021-03-03
    oval:org.opensuse.security:def:31738
    P
    Security update for grub2 (Important)
    2021-03-02
    oval:org.opensuse.security:def:31727
    P
    Security update for wpa_supplicant (Important)
    2021-02-15
    oval:org.opensuse.security:def:31726
    P
    Security update for the Linux Kernel (Important)
    2021-02-12
    oval:org.opensuse.security:def:31692
    P
    Security update for python3 (Important)
    2021-02-08
    oval:org.opensuse.security:def:31179
    P
    Security update for dovecot22 (Important)
    2021-01-04
    oval:org.opensuse.security:def:32020
    P
    Security update for cyrus-sasl (Important)
    2020-12-28
    oval:org.opensuse.security:def:25983
    P
    Security update for openexr (Moderate)
    2020-12-23
    oval:org.opensuse.security:def:25979
    P
    Security update for xen (Moderate)
    2020-12-18
    oval:org.opensuse.security:def:31093
    P
    Security update for the Linux Kernel (Live Patch 36 for SLE 12 SP3) (Important)
    2020-12-07
    oval:org.opensuse.security:def:31560
    P
    Security update for python-cryptography (Moderate)
    2020-12-04
    oval:org.opensuse.security:def:35625
    P
    pam_ldap-184-147.20 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:42032
    P
    pam_ldap-184-147.20 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35799
    P
    pam_ldap-184-147.20 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:36008
    P
    pam_ldap-184-147.20 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:25361
    P
    Security update for tomcat (Important)
    2020-12-01
    oval:org.opensuse.security:def:25691
    P
    Security update for python36 (Important)
    2020-12-01
    oval:org.opensuse.security:def:26763
    P
    libqt4-sql-mysql on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25558
    P
    Security update for systemd (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25842
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:26333
    P
    Security update for redis (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25809
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:26013
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26386
    P
    Security update for kdepim, messagelib (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26541
    P
    evince on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31547
    P
    Security update for sblim-sfcb (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31847
    P
    Security update for clamav (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32590
    P
    pam_ldap on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31981
    P
    Security update for java-1_7_1-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:32724
    P
    libpng12-0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31475
    P
    Security update for procps (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31784
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:32294
    P
    Security update for ppp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31944
    P
    Security update for gnutls (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32336
    P
    Security update for sane-backends (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32502
    P
    dhcp on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25176
    P
    Security update for dpdk (Important)
    2020-12-01
    oval:org.opensuse.security:def:25380
    P
    Security update for apache2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25753
    P
    Security update for flash-player (Important)
    2020-12-01
    oval:org.opensuse.security:def:25908
    P
    Security update for flash-player (Important)
    2020-12-01
    oval:org.opensuse.security:def:25425
    P
    Security update for bluez (Important)
    2020-12-01
    oval:org.opensuse.security:def:25775
    P
    Security update for flash-player (Important)
    2020-12-01
    oval:org.opensuse.security:def:26798
    P
    pam_ldap on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25569
    P
    Security update for tomcat (Important)
    2020-12-01
    oval:org.opensuse.security:def:25899
    P
    Security update for gd (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26236
    P
    Security update for libvpx (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26971
    P
    libsndfile on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25810
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:26439
    P
    Security update for MozillaThunderbird (Important)
    2020-12-01
    oval:org.opensuse.security:def:26585
    P
    libexif on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31869
    P
    Security update for curl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32763
    P
    pam_ldap on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31486
    P
    Security update for python (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31841
    P
    Security update for bzip2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:32036
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:32392
    P
    Security update for tomcat6 (Important)
    2020-12-01
    oval:org.opensuse.security:def:32546
    P
    libadns1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25177
    P
    Security update for mariadb-connector-c (Important)
    2020-12-01
    oval:org.opensuse.security:def:25461
    P
    Security update for cpio (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25806
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:25952
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:25349
    P
    Security update for bluez (Important)
    2020-12-01
    oval:org.opensuse.security:def:25553
    P
    Security update for mutt (Important)
    2020-12-01
    oval:org.opensuse.security:def:25926
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:25633
    P
    Security update for perl-DBI (Important)
    2020-12-01
    oval:org.opensuse.security:def:26275
    P
    Security update for freerdp (Important)
    2020-12-01
    oval:org.opensuse.security:def:27006
    P
    pam_ldap on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25821
    P
    Security update for lhasa (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26488
    P
    Security update for cacti, cacti-spine (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27223
    P
    libtspi1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31094
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:31403
    P
    Security update for perl-DBD-mysql (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31759
    P
    Security update for LibVNCServer (Important)
    2020-12-01
    oval:org.opensuse.security:def:31913
    P
    Security update for gcc5 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31484
    P
    Security update for python (Important)
    2020-12-01
    oval:org.opensuse.security:def:31876
    P
    Security update for dhcp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32042
    P
    Security update for krb5 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31928
    P
    Security update for giflib (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32441
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:33184
    P
    libsss_idmap0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25188
    P
    Security update for texlive (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25518
    P
    Security update for samba (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25855
    P
    Security update for flash-player (Critical)
    2020-12-01
    oval:org.opensuse.security:def:26590
    P
    libmusicbrainz4 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25350
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:25634
    P
    Security update for java-1_7_0-openjdk (Important)
    2020-12-01
    oval:org.opensuse.security:def:25557
    P
    Security update for transfig (Low)
    2020-12-01
    oval:org.opensuse.security:def:25761
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:26289
    P
    Security update for sane-backends (Important)
    2020-12-01
    oval:org.opensuse.security:def:25885
    P
    Security update for ImageMagick (Important)
    2020-12-01
    oval:org.opensuse.security:def:26235
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26527
    P
    boost-license on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27258
    P
    pam_ldap on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31105
    P
    Security update for kernel-source (Important)
    2020-12-01
    oval:org.opensuse.security:def:31460
    P
    Security update for postgresql94 (Important)
    2020-12-01
    oval:org.opensuse.security:def:31808
    P
    Security update for apache2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32551
    P
    libexiv2-4 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31576
    P
    Security update for sudo (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31932
    P
    Security update for libX11 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31474
    P
    Security update for procmail (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31812
    P
    Security update for apache2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:32480
    P
    MozillaFirefox on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33223
    P
    pam_ldap on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25252
    P
    Security update for ipmitool (Important)
    2020-12-01
    oval:org.opensuse.security:def:25602
    P
    Security update for java-1_7_1-ibm (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25894
    P
    Security update for gstreamer-0_10-plugins-bad (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26625
    P
    pam_ldap on GA media (Moderate)
    2020-12-01
    oval:org.mitre.oval:def:10418
    V
    pam_ldap in nss_ldap on Red Hat Enterprise Linux 4, Fedora Core 3 and earlier, and possibly other distributions does not return an error condition when an LDAP directory server responds with a PasswordPolicyResponse control response, which causes the pam_authenticate function to return a success code even if authentication has failed, as originally reported for xscreensaver.
    2013-04-29
    oval:com.redhat.rhsa:def:20060719
    P
    RHSA-2006:0719: nss_ldap security update (Moderate)
    2006-11-15
    oval:org.debian:def:1203
    V
    programming error
    2006-11-02
    BACK
    redhat enterprise linux 4.0
    fedoraproject fedora core *
    redhat enterprise linux 4.0
    redhat enterprise linux desktop 4.0
    redhat enterprise linux for ibm z systems 4.0_s390
    redhat enterprise linux for ibm z systems 4.0_s390x
    redhat enterprise linux for power big endian 4.0
    redhat enterprise linux server 4.0
    redhat enterprise linux workstation 4.0
    debian debian linux 3.1