CVE-2011-0438

Arthurdejong Nss-pam-ldapd - Authentication Bypass

Title source: rule

Description

nslcd/pam.c in the nss-pam-ldapd 0.8.0 PAM module returns a success code when a user is not found in LDAP, which allows remote attackers to bypass authentication.

Scores

EPSS 0.0044
EPSS Percentile 63.0%

Classification

CWE
CWE-287
Status draft

Affected Products (1)

arthurdejong/nss-pam-ldapd

Timeline

Published Mar 15, 2011
Tracked Since Feb 18, 2026