|
|
Log in / Subscribe / Register

Mageia alert MGASA-2016-0350 (389-ds-base)

From:  Mageia Updates <buildsystem-daemon@mageia.org>
To:  updates-announce@ml.mageia.org
Subject:  [updates-announce] MGASA-2016-0350: Updated 389-ds-base packages fix security vulnerability
Date:  Fri, 21 Oct 2016 16:48:59 +0200
Message-ID:  <20161021144859.654D29F7A2@duvel.mageia.org>

MGASA-2016-0350 - Updated 389-ds-base packages fix security vulnerability Publication date: 21 Oct 2016 URL: http://advisories.mageia.org/MGASA-2016-0350.html Type: security Affected Mageia releases: 5 CVE: CVE-2016-4992 Description: A vulnerability in 389-ds-base was found that allows to bypass limitations for compare and read operations specified by Access Control Instructions. When having LDAP sub-tree with some existing objects and having BIND DN which have no privileges over objects inside the sub-tree, unprivileged user can send LDAP ADD operation specifying an object in (supposedly) inaccessible sub-tree. The returned error messages discloses the information when the queried object exists having the specified value. Attacker can use this flaw to guess values of RDN component by repeating the above process (CVE-2016-4992). References: - https://bugs.mageia.org/show_bug.cgi?id=19304 - https://lists.fedoraproject.org/archives/list/package-ann... - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4992 SRPMS: - 5/core/389-ds-base-1.3.4.14-1.mga5


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds