Updated nss_ldap packages that fix a security flaw are now available for
Red Hat Enterprise Linux 4.
This update has been rated as having moderate security impact by the Red Hat
Security Response Team.
nss_ldap is a set of C library extensions that allow X.500 and LDAP
directory servers to be used as primary sources for aliases, ethers,
groups, hosts, networks, protocols, users, RPCs, services, and shadow
passwords.
A flaw was found in the way nss_ldap handled a PasswordPolicyResponse
control sent by an LDAP server. If an LDAP server responded to an
authentication request with a PasswordPolicyResponse control, it was
possible for an application using nss_ldap to improperly authenticate
certain users. (CVE-2006-5170)
This flaw was only exploitable within applications which did not properly
process nss_ldap error messages. Only xscreensaver is currently known to
exhibit this behavior.
All users of nss_ldap should upgrade to these updated packages, which
contain a backported patch that resolves this issue.
| Red Hat Desktop (v. 4) |
|
| SRPMS: |
nss_ldap-226-17.src.rpm
File outdated by: RHBA-2009:0986 |
8fdad6a352014e9c95f6640896bf91dd |
| |
| IA-32: |
nss_ldap-226-17.i386.rpm
File outdated by: RHBA-2009:0986 |
f2728f30aeb7e78623aae9265fae7369 |
| |
| x86_64: |
nss_ldap-226-17.i386.rpm
File outdated by: RHBA-2009:0986 |
f2728f30aeb7e78623aae9265fae7369 |
nss_ldap-226-17.x86_64.rpm
File outdated by: RHBA-2009:0986 |
804dba9f8720306da14615b1f353e31d |
| |
| Red Hat Enterprise Linux AS (v. 4) |
|
| SRPMS: |
nss_ldap-226-17.src.rpm
File outdated by: RHBA-2009:0986 |
8fdad6a352014e9c95f6640896bf91dd |
| |
| IA-32: |
nss_ldap-226-17.i386.rpm
File outdated by: RHBA-2009:0986 |
f2728f30aeb7e78623aae9265fae7369 |
| |
| IA-64: |
nss_ldap-226-17.i386.rpm
File outdated by: RHBA-2009:0986 |
f2728f30aeb7e78623aae9265fae7369 |
nss_ldap-226-17.ia64.rpm
File outdated by: RHBA-2009:0986 |
a8cc0cd2d3bd8f2fa916b8f50506dbfa |
| |
| PPC: |
nss_ldap-226-17.ppc.rpm
File outdated by: RHBA-2009:0986 |
8fe0c5612ddac345de98d98daf3b1f47 |
nss_ldap-226-17.ppc64.rpm
File outdated by: RHBA-2009:0986 |
fef89f4ddf2879df5d8b3cad563610dc |
| |
| s390: |
nss_ldap-226-17.s390.rpm
File outdated by: RHBA-2009:0986 |
07f25516c0a7c24c8119f440f4c1fdf0 |
| |
| s390x: |
nss_ldap-226-17.s390.rpm
File outdated by: RHBA-2009:0986 |
07f25516c0a7c24c8119f440f4c1fdf0 |
nss_ldap-226-17.s390x.rpm
File outdated by: RHBA-2009:0986 |
e193a588cce944b5fa2a3feb01737b61 |
| |
| x86_64: |
nss_ldap-226-17.i386.rpm
File outdated by: RHBA-2009:0986 |
f2728f30aeb7e78623aae9265fae7369 |
nss_ldap-226-17.x86_64.rpm
File outdated by: RHBA-2009:0986 |
804dba9f8720306da14615b1f353e31d |
| |
| Red Hat Enterprise Linux ES (v. 4) |
|
| SRPMS: |
nss_ldap-226-17.src.rpm
File outdated by: RHBA-2009:0986 |
8fdad6a352014e9c95f6640896bf91dd |
| |
| IA-32: |
nss_ldap-226-17.i386.rpm
File outdated by: RHBA-2009:0986 |
f2728f30aeb7e78623aae9265fae7369 |
| |
| IA-64: |
nss_ldap-226-17.i386.rpm
File outdated by: RHBA-2009:0986 |
f2728f30aeb7e78623aae9265fae7369 |
nss_ldap-226-17.ia64.rpm
File outdated by: RHBA-2009:0986 |
a8cc0cd2d3bd8f2fa916b8f50506dbfa |
| |
| x86_64: |
nss_ldap-226-17.i386.rpm
File outdated by: RHBA-2009:0986 |
f2728f30aeb7e78623aae9265fae7369 |
nss_ldap-226-17.x86_64.rpm
File outdated by: RHBA-2009:0986 |
804dba9f8720306da14615b1f353e31d |
| |
| Red Hat Enterprise Linux WS (v. 4) |
|
| SRPMS: |
nss_ldap-226-17.src.rpm
File outdated by: RHBA-2009:0986 |
8fdad6a352014e9c95f6640896bf91dd |
| |
| IA-32: |
nss_ldap-226-17.i386.rpm
File outdated by: RHBA-2009:0986 |
f2728f30aeb7e78623aae9265fae7369 |
| |
| IA-64: |
nss_ldap-226-17.i386.rpm
File outdated by: RHBA-2009:0986 |
f2728f30aeb7e78623aae9265fae7369 |
nss_ldap-226-17.ia64.rpm
File outdated by: RHBA-2009:0986 |
a8cc0cd2d3bd8f2fa916b8f50506dbfa |
| |
| x86_64: |
nss_ldap-226-17.i386.rpm
File outdated by: RHBA-2009:0986 |
f2728f30aeb7e78623aae9265fae7369 |
nss_ldap-226-17.x86_64.rpm
File outdated by: RHBA-2009:0986 |
804dba9f8720306da14615b1f353e31d |
| |
(The unlinked packages above are only available from the Red Hat Network)
|
207286 - CVE-2006-5170 When using LDAP for authentication, xscreensaver allows access if account locked out.