Medium severity5.5NVD Advisory· Published Mar 31, 2009· Updated Apr 23, 2026
CVE-2009-1073
CVE-2009-1073
Description
nss-ldapd before 0.6.8 uses world-readable permissions for the /etc/nss-ldapd.conf file, which allows local users to obtain a cleartext password for the LDAP server by reading the bindpw field.
Affected products
2- cpe:2.3:o:debian:debian_linux:5.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
12- bugs.debian.org/cgi-bin/bugreport.cginvdMailing ListPatch
- www.debian.org/security/2009/dsa-1758nvdPatchThird Party Advisory
- arthurenhella.demon.nl/viewvc/nss-ldapd/nss-ldapd/debian/libnss-ldapd.postinstnvdBroken LinkExploit
- launchpad.net/bugs/cve/2009-1073nvdThird Party Advisory
- www.securityfocus.com/bid/34211nvdBroken LinkThird Party AdvisoryVDB Entry
- arthurenhella.demon.nl/viewvc/nss-ldapd/nss-ldapd/man/nss-ldapd.conf.5.xmlnvdBroken Link
- ch.tudelft.nl/~arthur/nss-ldapd/news.htmlnvdBroken Link
- secunia.com/advisories/34523nvdBroken Link
- www.openwall.com/lists/oss-security/2009/03/23/3nvdMailing List
- www.openwall.com/lists/oss-security/2009/03/24/2nvdMailing List
- www.openwall.com/lists/oss-security/2009/03/25/3nvdMailing List
- www.openwall.com/lists/oss-security/2009/03/25/4nvdMailing List
News mentions
0No linked articles in our index yet.