CVE-2011-0438
Arthurdejong Nss-pam-ldapd - Authentication Bypass
Title source: ruleDescription
nslcd/pam.c in the nss-pam-ldapd 0.8.0 PAM module returns a success code when a user is not found in LDAP, which allows remote attackers to bypass authentication.
References (6)
Scores
EPSS
0.0044
EPSS Percentile
63.0%
Classification
CWE
CWE-287
Status
draft
Affected Products (1)
arthurdejong/nss-pam-ldapd
Timeline
Published
Mar 15, 2011
Tracked Since
Feb 18, 2026