Unrated severityNVD Advisory· Published Mar 15, 2011· Updated Jun 16, 2026
CVE-2011-0438
CVE-2011-0438
Description
nslcd/pam.c in the nss-pam-ldapd 0.8.0 PAM module returns a success code when a user is not found in LDAP, which allows remote attackers to bypass authentication.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- cpe:2.3:a:arthurdejong:nss-pam-ldapd:0.8.0:*:*:*:*:*:*:*
- Range: = 0.8.0
Patches
Vulnerability mechanics
References
6- lists.arthurdejong.org/nss-pam-ldapd-announce/2011/attachments/txtVf3rHgt8qQ.txtnvdPatch
- lists.arthurdejong.org/nss-pam-ldapd-announce/2011/msg00000.htmlnvdPatchVendor Advisory
- www.securityfocus.com/bid/46819nvdPatch
- arthurdejong.org/nss-pam-ldapd/news.htmlnvd
- securityreason.com/securityalert/8132nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/66028nvd
News mentions
0No linked articles in our index yet.