LWN.net Logo

389-ds-base: information disclosure

Package(s):389-ds-base CVE #(s):CVE-2013-2219
Created:July 31, 2013 Updated:July 31, 2013
Description: From the Red Hat advisory:

It was discovered that the 389 Directory Server did not honor defined attribute access controls when evaluating search filter expressions. A remote attacker (with permission to query the Directory Server) could use this flaw to determine the values of restricted attributes via a series of search queries with filter conditions that used restricted attributes.

Alerts:
Red Hat RHSA-2013:1119-01 2013-07-30
CentOS CESA-2013:1119 2013-07-30
Oracle ELSA-2013-1119 2013-07-30
Scientific Linux SL-389--20130730 2013-07-30
Fedora FEDORA-2013-15540 2013-08-30
Mageia MGASA-2013-0263 2013-08-30

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds