Security Advisory

CVE-2009-1073

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2009-03-31 18:00:00
Last updated 2024-08-07 04:57:17
Assigner mitre
State PUBLISHED

Description

nss-ldapd before 0.6.8 uses world-readable permissions for the /etc/nss-ldapd.conf file, which allows local users to obtain a cleartext password for the LDAP server by reading the bindpw field.