CVE-2009-1073: Medium severity Debian Nss-ldap vulnerability
nss-ldapd before 0.6.8 uses world-readable permissions for the /etc/nss-ldapd.conf file, which allows local users to obtain a cleartext password for the LDAP server by reading the bindpw field.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1073?
CVE-2009-1073 is considered a moderate severity vulnerability due to improper file permissions that could allow local users to access sensitive information.
How do I fix CVE-2009-1073?
To fix CVE-2009-1073, update nss-ldapd to version 0.6.8 or later, which addresses the permissions issue.
What are the risks associated with CVE-2009-1073?
The risks associated with CVE-2009-1073 include unauthorized access to cleartext passwords of the LDAP server, potentially leading to further system compromises.
Which versions of nss-ldapd are affected by CVE-2009-1073?
Versions of nss-ldapd prior to 0.6.8 are affected by CVE-2009-1073.
How can I verify if my system is vulnerable to CVE-2009-1073?
You can verify if your system is vulnerable to CVE-2009-1073 by checking the permissions of the /etc/nss-ldapd.conf file and confirming the version of nss-ldapd installed.