SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#778916

pam_ldap authentication bypass vulnerability

Overview

An error in the pam_ldap password policy control may allow a remote attacker to gain access to a system.

I. Description

pam_ldap provides LDAP authentication services for UNIX-based systems. A vulnerability in pam_ldap may allow a remote attacker to bypass the authentication mechanism. If a pam_ldap client attempts to authenticate against an LDAP server that omits the optional error value from the PasswordPolicyResponseValue, the authentication attempt will always succeed.

Note that this vulnerability affects all versions of pam_ldap since version pam_ldap-169. However, if the underlying LDAP client library does not support LDAP version 3 controls, then this vulnerability is not present.

II. Impact

An unauthenticated, remote attacker may be able to bypass the pam_ldap authentication mechanism and gain access to a system, possibly with elevated privileges.

III. Solution

Upgrade pam_ldap

This vulnerability was corrected in pam_ldap-180.

Systems Affected

VendorStatusDate NotifiedDate Updated
Apple Computer, Inc.Not Vulnerable10-Oct-2005
Computer AssociatesUnknown19-Aug-2005
Debian LinuxVulnerable25-Aug-2005
Engarde Secure LinuxUnknown19-Aug-2005
Hewlett-Packard CompanyNot Vulnerable31-Aug-2005
HitachiNot Vulnerable15-Sep-2005
IBM CorporationUnknown19-Aug-2005
IBM Corporation (zseries)Unknown19-Aug-2005
IBM eServerUnknown19-Aug-2005
Immunix Communications, Inc.Unknown19-Aug-2005
Ingrian Networks, Inc.Unknown19-Aug-2005
Lotus SoftwareUnknown19-Aug-2005
Mandriva, Inc.Unknown19-Aug-2005
Mandriva, Inc.Unknown19-Aug-2005
Microsoft CorporationNot Vulnerable28-Sep-2005
Mirapoint, Inc.Unknown19-Aug-2005
MontaVista Software, Inc.Unknown19-Aug-2005
Netscape Communications CorporationUnknown19-Aug-2005
Novell, Inc.Unknown19-Aug-2005
OctetString, Inc.Unknown19-Aug-2005
OpenLDAPUnknown19-Aug-2005
Openwall GNU/*/LinuxNot Vulnerable6-Sep-2005
Oracle CorporationNot Vulnerable6-Sep-2005
PADLVulnerable25-Aug-2005
QUALCOMM IncorporatedUnknown19-Aug-2005
Red Hat, Inc.Vulnerable2-Nov-2005
Sequent Computer Systems, Inc.Unknown19-Aug-2005
Sun Microsystems, Inc.Not Vulnerable2-Sep-2005
SUSE LinuxNot Vulnerable22-Aug-2005
The SCO Group (SCO Linux)Unknown19-Aug-2005
The Teamware GroupUnknown19-Aug-2005
TurbolinuxUnknown19-Aug-2005

References


http://www.padl.com/OSS/pam_ldap.html
http://secunia.com/advisories/16518/

Credit

This vulnerability was reported by Luke Howard of PADL.

This document was written by Jeff Gennari.

Other Information

Date Public:2005-08-24
Date First Published:2005-08-24
Date Last Updated:2005-11-02
CERT Advisory: 
CVE-ID(s):CAN-2005-2641
NVD-ID(s):CAN-2005-2641
US-CERT Technical Alerts: 
Metric:8.15
Document Revision:54

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2005 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader