Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
pam_ldap and nss_ldap, when used with OpenLDAP and connecting to a slave using TLS, does not use TLS for the subsequent connection if the client is referred to a master, which may cause a password to be sent in cleartext and allows remote attackers to sniff the password.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
OpenLDAP 安全漏洞
Vulnerability Description
OpenLDAP是美国OpenLDAP基金会的一个轻型目录访问协议(LDAP)的开源实现。 OpenLDAP 存在安全漏洞,该漏洞源于在同TLS一起使用时在口令的传输处理上存在漏洞,攻击者可能利用此漏洞获取明文口令。如果在使用TLS与从盘建立连接且客户端用作主盘的话,就会出现这个漏洞。TLS没有使用这个连接,这可能导致以明文发送口令,允许攻击者嗅探到口令。
CVSS Information
N/A
Vulnerability Type
N/A