Vulnerabilities
Vulnerable Software
Arthurdejong:  Security Vulnerabilities
nss-pam-ldapd before 0.7.18 and 0.8.x before 0.8.11 allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code by performing a name lookup on an application with a large number of open file descriptors, which triggers a stack-based buffer overflow related to incorrect use of the FD_SET macro.
CVSS Score
6.8
EPSS Score
0.029
Published
2013-03-05
nslcd/pam.c in the nss-pam-ldapd 0.8.0 PAM module returns a success code when a user is not found in LDAP, which allows remote attackers to bypass authentication.
CVSS Score
6.8
EPSS Score
0.004
Published
2011-03-15


Contact Us

Shodan ® - All rights reserved