|
|
| |
|
| |
389-ds-base: information disclosure
| Package(s): | 389-ds-base |
CVE #(s): | CVE-2013-2219
|
| Created: | July 31, 2013 |
Updated: | July 31, 2013 |
| Description: |
From the Red Hat advisory:
It was discovered that the 389 Directory Server did not honor defined
attribute access controls when evaluating search filter expressions. A
remote attacker (with permission to query the Directory Server) could use
this flaw to determine the values of restricted attributes via a series of
search queries with filter conditions that used restricted attributes. |
| Alerts: |
|
( Log in to post comments)
|
|
|