First published: Sun Aug 21 2005(Updated: )
Unknown vulnerability in pam_ldap before 180 does not properly handle a new password policy control, which could allow attackers to gain privileges. NOTE: CVE-2005-2497 had also been assigned to this issue, but CVE-2005-2641 is the correct candidate.
Credit: security@debian.org
Affected Software | Affected Version | How to fix |
---|---|---|
SUSE PAM Ldap | <=build_178 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2641 has a medium severity level due to its potential to allow privilege escalation.
To remediate CVE-2005-2641, update pam_ldap to version 180 or later.
CVE-2005-2641 affects pam_ldap versions up to and including build 178.
CVE-2005-2641 is a privilege escalation vulnerability related to password policy control handling.
Exploitation of CVE-2005-2641 generally requires local access to the system.