nss-ldapd before 0.6.8 uses world-readable permissions...
Moderate severity
Unreviewed
Published
May 2, 2022
to the GitHub Advisory Database
•
Updated Feb 24, 2024
Description
Published by the National Vulnerability Database
Mar 31, 2009
Published to the GitHub Advisory Database
May 2, 2022
Last updated
Feb 24, 2024
nss-ldapd before 0.6.8 uses world-readable permissions for the /etc/nss-ldapd.conf file, which allows local users to obtain a cleartext password for the LDAP server by reading the bindpw field.
References