MGASA-2016-0350

Source
https://advisories.mageia.org/MGASA-2016-0350.html
Import Source
https://advisories.mageia.org/MGASA-2016-0350.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2016-0350
Related
Published
2016-10-21T14:48:32Z
Modified
2016-10-21T07:59:51Z
Summary
Updated 389-ds-base packages fix security vulnerability
Details

A vulnerability in 389-ds-base was found that allows to bypass limitations for compare and read operations specified by Access Control Instructions. When having LDAP sub-tree with some existing objects and having BIND DN which have no privileges over objects inside the sub-tree, unprivileged user can send LDAP ADD operation specifying an object in (supposedly) inaccessible sub-tree. The returned error messages discloses the information when the queried object exists having the specified value. Attacker can use this flaw to guess values of RDN component by repeating the above process (CVE-2016-4992).

References
Credits

Affected packages