Package name
Advisory ID
Affected versions
9.1 i586 , 9.1 i586

Problem description

A bug was fixed in pam_ldap 162 with the pam_filter mechanism which is commonly used for host-based access restriction in environments using LDAP for authentication. Mandrake Linux 9.1 provided pam_ldap 161 which had this problem and as a result, systems relying on pam_filter for host-based access restriction would allow any user, regardless of the host attribute associated with their account, to log into the system. All users who use LDAP-based authentication are encouraged to upgrade immediately.

Updated packages

9.1 i586

 6877e2f9a684bb4bb411fb8392278a40  ppc/9.1/RPMS/nss_ldap-207-1.1mdk.ppc.rpm
76281fc9940fad0d56436056223f6b88  ppc/9.1/RPMS/pam_ldap-164-1.1mdk.ppc.rpm
501d4588893ef392de909003094fa7bd  ppc/9.1/SRPMS/nss_ldap-207-1.1mdk.src.rpm

9.1 i586

 d02470a4054c4172e3d5cad24e6edf00  9.1/RPMS/nss_ldap-207-1.1mdk.i586.rpm
8604487f7ec6342d9c5c3e0ba81fbbea  9.1/RPMS/pam_ldap-164-1.1mdk.i586.rpm
501d4588893ef392de909003094fa7bd  9.1/SRPMS/nss_ldap-207-1.1mdk.src.rpm