Unrated severityNVD Advisory· Published Jan 9, 2006· Updated Apr 16, 2026
CVE-2006-0150
CVE-2006-0150
Description
Multiple format string vulnerabilities in the auth_ldap_log_reason function in Apache auth_ldap 1.6.0 and earlier allows remote attackers to execute arbitrary code via various vectors, including the username.
Affected products
13cpe:2.3:a:dave_carrigan:auth_ldap:1.2.1:*:*:*:*:*:*:*+ 12 more
- cpe:2.3:a:dave_carrigan:auth_ldap:1.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:dave_carrigan:auth_ldap:1.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:dave_carrigan:auth_ldap:1.2.3:*:*:*:*:*:*:*
- cpe:2.3:a:dave_carrigan:auth_ldap:1.2.4:*:*:*:*:*:*:*
- cpe:2.3:a:dave_carrigan:auth_ldap:1.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:dave_carrigan:auth_ldap:1.3.1:*:*:*:*:*:*:*
- cpe:2.3:a:dave_carrigan:auth_ldap:1.3.2:*:*:*:*:*:*:*
- cpe:2.3:a:dave_carrigan:auth_ldap:1.3.3:*:*:*:*:*:*:*
- cpe:2.3:a:dave_carrigan:auth_ldap:1.3.4:*:*:*:*:*:*:*
- cpe:2.3:a:dave_carrigan:auth_ldap:1.4.0:*:*:*:*:*:*:*
- cpe:2.3:a:dave_carrigan:auth_ldap:1.4.2:*:*:*:*:*:*:*
- cpe:2.3:a:dave_carrigan:auth_ldap:1.4.3:*:*:*:*:*:*:*
- cpe:2.3:a:dave_carrigan:auth_ldap:1.6.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
14- secunia.com/advisories/18382nvdPatchVendor Advisory
- secunia.com/advisories/18405nvdPatchVendor Advisory
- secunia.com/advisories/18412nvdPatchVendor Advisory
- secunia.com/advisories/18568nvdPatchVendor Advisory
- www.debian.org/security/2006/dsa-952nvdPatchVendor Advisory
- www.redhat.com/support/errata/RHSA-2006-0179.htmlnvdPatchVendor Advisory
- www.securityfocus.com/bid/16177nvdPatch
- wwwnew.mandriva.com/security/advisoriesnvdPatchVendor Advisory
- www.digitalarmaments.com/2006090173928420.htmlnvdVendor AdvisoryURL Repurposed
- www.vupen.com/english/advisories/2006/0117nvdVendor Advisory
- securitytracker.com/idnvd
- www.rudedog.org/auth_ldap/Changes.htmlnvd
- www.securityfocus.com/archive/1/421286/100/0/threadednvd
- exchange.xforce.ibmcloud.com/vulnerabilities/24030nvd
News mentions
0No linked articles in our index yet.