Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 150294 - sys-auth/nss_ldap allows trivial local-console access to locked accounts
Summary: sys-auth/nss_ldap allows trivial local-console access to locked accounts
Status: RESOLVED INVALID
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal
Assignee: Gentoo Security
URL: http://www.cve.mitre.org/cgi-bin/cven...
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2006-10-06 08:51 UTC by Matt Drew (RETIRED)
Modified: 2006-10-11 06:18 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Matt Drew (RETIRED) gentoo-dev 2006-10-06 08:51:58 UTC
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=207286
https://issues.rpath.com/browse/RPL-680

The Red Hat bug is x86_64, but the rpath bug doesn't report platform and the CVE links to several advisories that update all platforms (Mandriva, for instance).

This is an old bug that just popped up again on fulldiclosure, I searched up and down in bugzilla but didn't see it.  We still have vulnerable versions in portage (see bug #140490, security cleanup needed).  Current stable is 249, which fixes this particular problem.
Comment 1 Matthias Geerdsen (RETIRED) gentoo-dev 2006-10-11 06:18:14 UTC
Thanks for the report.

Since the stable version is not affected and has been stable for months, this does not appear to be worth a GLSA anymore.
The older versions are also vulnerable to a different issue, so they really should be removed when possible, but this is handled in bug #140490.