Bug#444172: [Pkg-openldap-devel] Bug#444172: slapd: accepts incorrect passwords

2007-09-27 Thread Quanah Gibson-Mount
--On Thursday, September 27, 2007 10:45 PM +0200 Paweł Pałucha <[EMAIL PROTECTED]> wrote: Quanah Gibson-Mount wrote: I'm able to reproduce it using just ldapsearch: ldapsearch -b 'ou=People,dc=praterm,dc=pl' -D \ 'uid=pawel,ou=People,dc=praterm,dc=pl' -x -W It asks for password and acce

Bug#444172: [Pkg-openldap-devel] Bug#444172: slapd: accepts incorrect passwords

2007-09-26 Thread Quanah Gibson-Mount
--On Wednesday, September 26, 2007 4:50 PM +0200 Pawel Palucha <[EMAIL PROTECTED]> wrote: Package: slapd Version: 2.3.38-1 Severity: normal When binding to slapd I can pass any password that starts with correct password and it is accepted (for example, if password is '1234', also '12345' is a

Bug#444172: slapd: accepts incorrect passwords

2007-09-26 Thread Pawel Palucha
Package: slapd Version: 2.3.38-1 Severity: normal When binding to slapd I can pass any password that starts with correct password and it is accepted (for example, if password is '1234', also '12345' is accepted). Checked with python bindings and apache ldap_auth module. {CRYPT} is used to hash pa