LWN.net Logo

389-ds-base: ACL restriction bypass

Package(s):389-ds-base CVE #(s):CVE-2012-4450
Created:January 15, 2013 Updated:March 11, 2013
Description: From the CVE entry:

389 Directory Server 1.2.10 does not properly update the ACL when a DN entry is moved by a modrdn operation, which allows remote authenticated users with certain permissions to bypass ACL restrictions and access the DN entry.

Alerts:
Fedora FEDORA-2012-20156 2013-01-15
Red Hat RHSA-2013:0503-03 2013-02-21
Oracle ELSA-2013-0503 2013-02-25
Scientific Linux SL-389--20130228 2013-02-28
CentOS CESA-2013:0503 2013-03-09

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds