Debian Security Advisory 1517-1 – Don Armstrong discovered that ldapscripts, a suite of tools to manipulate user accounts in LDAP, sends the password as a command line argument when calling LDAP programs, which may allow a local attacker to read this password from the process listing.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/64618/dsa-1517-1.txt
Source: https://packetstormsecurity.com/files/64618/Debian-Linux-Security-Advisory-1517-1.html

