Linux Compatible
  • News
    • Channels
    • Archive
    • Search
    • Submit
  • Articles
    • Categories
  • Knowledgebase
  • Compatibility
    • Search
  • Links
  • Forums
  • Twitter
Advertisement

Latest News
[ Windows | Linux | Apple ]

· Apple Seeds First OS X 10.8.5 Beta to Developers
· Microsoft will pay up to $100K for new Windows exploit techniques
· DSA 2711-1: haproxy security update
· System Builder Marathon, Q2 2013 and more
· Microsoft delivers biggest update to date to TypeScript
· Tiff/nss-pam-ldapd Updates for Debian
· Update for Windows 8/Server 2012
· Apple TV 5.4 beta adds iTunes Radio, Conference Room Display
· DSA 2710-1: xml-security-c security update
· Intel DZ87KLT-75K Kinsley Thunderbolt Motherboard Review

Upcoming News
· EVGA GeForce GTX 780 ACX SC Review @ Hardware Canucks
· MSI FM2-A85XMA-E35 Micro ATX Motherboard Review @ HiTech Legion
· Thermaltake Urban S31 Chassis Review
· [RHSA-2013:0957-01] Critical: java-1.7.0-openjdk security update
· [RHSA-2013:0958-01] Important: java-1.7.0-openjdk security update
· Kingston HyperX Beast Black 16 GB 2133 C11 (2x8 GB) @ techPowerUp
· Canon PowerShot N Review @ TechReviewSource.com
· Gunpoint Review (PC)
· E3 2013: Wrap Up Coverage @ Legit Reviews
· Cougar Spike Micro ATX Case @ LanOC Reviews

Linux Compatibility
· Dell Dimension 9100
· CL-CAM50001 UPC=3700284609322
· DFE 520 TX
· nVidia GeForce4 MX 440
· Gore: Ultimate Soldier
· SMC2802W V2 wi-fi 54Mbps PCI card
· Wireless modem router N300
· Dell P780
· ASUS A7V8X
· BricsCAD for Linux

New Forum Topics
· Building a new PC: how EXACTLY to install USB mouse?
by: joyask43
on: 2013-06-09 14:36
6 replies, 2675 views

· Packet CD
by: natalieksh5
on: 2013-06-06 14:19
4 replies, 3455 views

· THE SIMS 2 DIRECTX 9.0C ERROR MESSAGE!! HELP! URGENT!!
by: tandrask34
on: 2013-06-05 14:06
28 replies, 93240 views

· Hello
by: barryherne
on: 2013-06-05 13:09
0 replies, 185 views

· shutdown link ?
by: estirwent
on: 2013-05-11 17:46
18 replies, 6900 views

News Channels
· Drivers
· Guides
· Reviews
· Security
· Software
· Press Release
· Updates
· Interviews
· Linux
· General
· Debian
· Red Hat
· Slackware
· Gentoo
· Mandriva
· White Box
· SUSE
· GNOME
· KDE
· CentOS
· Ubuntu
· MEPIS
· Android

What's New
Login to see an overview of all news stories since your last visit.

Welcome to our website

To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.

Linux Compatible » News » October 2005 » MDKSA-2005:190 - Updated nss_ldap/pam_ldap packages fix privilege vulnerabilities.

MDKSA-2005:190 - Updated nss_ldap/pam_ldap packages fix privilege vulnerabilities.

Posted by Bob on: 10/21/2005 08:12 AM [ Print | 0 comment(s) ]

The Mandriva Security Team published a new security update: MDKSA-2005:190 - Updated nss_ldap/pam_ldap packages fix privilege vulnerabilities. for Mandriva Linux. Here the announcement:




-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

_______________________________________________________________________

Mandriva Linux Security Update Advisory
_______________________________________________________________________

Package name: nss_ldap
Advisory ID: MDKSA-2005:190
Date: October 20th, 2005

Affected versions: 10.1, 10.2
______________________________________________________________________

Problem Description:

A bug was found in the way the pam_ldap module processed certain failure
messages. If the server includes supplemental data in an authentication
failure result message, but the data does not include any specific error
code, the pam_ldap module would proceed as if the authentication request
had succeeded, and authentication would succeed. This affects versions
169 through 179 of pam_ldap.

The updated packages have been patched to address this issue.
_______________________________________________________________________

References:

http://cve.mitre.org/cgi-bin/cvename.cgi?nameÊN-2005-2641
______________________________________________________________________

Updated Packages:

Mandrivalinux 10.1:
3cf5ab097f8e69b9e1ace711537fcb46 10.1/RPMS/nss_ldap-220-3.2.101mdk.i586.rpm
e5d3c8684a35cc147943b0b4a1922a42 10.1/RPMS/pam_ldap-170-3.2.101mdk.i586.rpm
edad8885447d4d059ff1c689ee6a6f7d 10.1/SRPMS/nss_ldap-220-3.2.101mdk.src.rpm

Mandrivalinux 10.1/X86_64:
7b8c8c7c40c30963aff186adffc94324 x86_64/10.1/RPMS/nss_ldap-220-3.2.101mdk.x86_64.rpm
ecbaa427c916e7fab0c355a91e04ee98 x86_64/10.1/RPMS/pam_ldap-170-3.2.101mdk.x86_64.rpm
edad8885447d4d059ff1c689ee6a6f7d x86_64/10.1/SRPMS/nss_ldap-220-3.2.101mdk.src.rpm

Mandrivalinux 10.2:
19950ddbfe52c8f0aa6e11ed93c59737 10.2/RPMS/pam_ldap-170-5.3.102mdk.i586.rpm
dab9943bb867001a4a4e514ffc58d84e 10.2/RPMS/nss_ldap-220-5.3.102mdk.i586.rpm
08e82d8a5fdcdd1620d8a22ec002173d 10.2/SRPMS/nss_ldap-220-5.3.102mdk.src.rpm

Mandrivalinux 10.2/X86_64:
54ff3f02df2e5f7c11564488784fc3ab x86_64/10.2/RPMS/nss_ldap-220-5.3.102mdk.x86_64.rpm
9d5541f3ac77d8ce6e2b8877b25f8980 x86_64/10.2/RPMS/pam_ldap-170-5.3.102mdk.x86_64.rpm
08e82d8a5fdcdd1620d8a22ec002173d x86_64/10.2/SRPMS/nss_ldap-220-5.3.102mdk.src.rpm
_______________________________________________________________________

To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:

gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

You can view other update advisories for Mandriva Linux at:

http://www.mandriva.com/security/advisories

If you want to report vulnerabilities, please contact

security_(at)_mandriva.com
_______________________________________________________________________

Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team
lt;security*mandriva.comgt;

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)

iD8DBQFDWImbmqjQ0CJFipgRAgX8AJ4jyjMmvr+bQ0j4kimAmSySxfnBTACgz4n5
cXO1suU5/bUFVM9e/Q5KKXo=
=jVbI
-----END PGP SIGNATURE-----


Bookmark and Share

« MDKSA-2005:192 - Updated xli packages fix buffer overflow vulnerabilities. · MDKSA-2005:191 - Updated ruby packages fix safe level and taint flag protections vulnerability »

Linux Compatible » News » October 2005 » MDKSA-2005:190 - Updated nss_ldap/pam_ldap packages fix privilege vulnerabilities.
All products mentioned are registered trademarks or trademarks of their respective owners.
© 2002-2013 Esselbach Internet Solutions - All Rights Reserved. Terms and privacy policy
Powered by Contentteller® Business Edition