1 results (0.005 seconds)
CVSS: 9.8EPSS: 2%CPEs: 10EXPL: 0

CVE-2006-5170
https://notcve.org/view.php?id=CVE-2006-5170
04 Oct 2006 — pam_ldap in nss_ldap on Red Hat Enterprise Linux 4, Fedora Core 3 and earlier, and possibly other distributions does not return an error condition when an LDAP directory server responds with a PasswordPolicyResponse control response, which causes the pam_authenticate function to return a success code even if authentication has failed, as originally reported for xscreensaver. pam_ldap en nss_ldap sobre Red Hat Enterprise Linux 4, Fedora Core 3 y anteriores, y posiblemente otras distribuciones no devuelven un... • http://bugzilla.padl.com/show_bug.cgi?id=291 • CWE-755: Improper Handling of Exceptional Conditions •