Gentoo Security Advisory GLSA 200507-13 (pam_ldap nss_ldap)

Summary
The remote host is missing updates announced in advisory GLSA 200507-13.
Solution
All pam_ldap users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose '>=sys-auth/pam_ldap-178-r1' All nss_ldap users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose sys-auth/nss_ldap http://www.securityspace.com/smysecure/catid.html?in=GLSA%20200507-13 http://bugs.gentoo.org/show_bug.cgi?id=96767
Insight
pam_ldap and nss_ldap fail to restart TLS when following a referral, possibly leading to credentials being sent in plain text.