pam_ldap: plain text authentication leak
| Package(s): | pam_ldap | CVE #(s): | CAN-2005-2069 | ||||||||||||||||||||||||
| Created: | July 14, 2005 | Updated: | October 17, 2005 | ||||||||||||||||||||||||
| Description: | pam_ldap and nss_ldap ignore the "ssl start_tls" ldap.conf setting, allowing an attacker to sniff unencrypted passwords and other information. | ||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||
