|
PADL Software PAM_LDAP TLS Plaintext Password Vulnerability
Solution: Trustix has released advisory TSLSA-2005-0031 to address various issues. Please see the referenced advisory for more information. Gentoo has released advisory GLSA 200507-13 to address this issue. Please see the referenced advisory for more information. Gentoo users may carry out the following commands to update their computers: All pam_ldap users: emerge --sync emerge --ask --oneshot --verbose ">=sys-auth/pam_ldap-178-r1" All nss_ldap users: emerge --sync emerge --ask --oneshot --verbose sys-auth/nss_ldap Mandriva had released security advisory MDKSA-2005:121 addressing this issue. Please see the referenced advisory for further information. Ubuntu Linux has released security advisory USN-152-1 addressing this issue. Please see the referenced advisory for details on obtaining and applying the appropriate updates. Turbolinux has released advisories TLSA-2005-86 and TLSA-2005-87 to address this issue in nss_ldap and pam_ldap, respectively. Please see the referenced advisories for further information. SUSE has released a security summary report (SUSE-SR:2005:020) addressing this and other issues. Please see the referenced advisory for further information. Conectiva Linux has released security advisory CLSA-2005:1027 addressing this issue. Please see the referenced advisory for details on obtaining and applying the appropriate updates. RedHat has released advisory RHSA-2005:767-8, along with fixes to address this issue in RedHat Enterprise operating systems. Please see the referenced advisory for further information. SGI has released advisory 20051003-01-U and fixes for this and other issues. Please see the referenced advisory for further details. Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: vuldb@securityfocus.com <mailto:vuldb@securityfocus.com>. Padl Software pam_ldap Build 111
Padl Software pam_ldap Build 164
Padl Software pam_ldap Build 148
Conectiva Linux 10.0
|
|
|
Privacy Statement |