Mageia alert MGASA-2016-0350 (389-ds-base)
| From: | Mageia Updates <buildsystem-daemon@mageia.org> | |
| To: | updates-announce@ml.mageia.org | |
| Subject: | [updates-announce] MGASA-2016-0350: Updated 389-ds-base packages fix security vulnerability | |
| Date: | Fri, 21 Oct 2016 16:48:59 +0200 | |
| Message-ID: | <20161021144859.654D29F7A2@duvel.mageia.org> |
MGASA-2016-0350 - Updated 389-ds-base packages fix security vulnerability Publication date: 21 Oct 2016 URL: http://advisories.mageia.org/MGASA-2016-0350.html Type: security Affected Mageia releases: 5 CVE: CVE-2016-4992 Description: A vulnerability in 389-ds-base was found that allows to bypass limitations for compare and read operations specified by Access Control Instructions. When having LDAP sub-tree with some existing objects and having BIND DN which have no privileges over objects inside the sub-tree, unprivileged user can send LDAP ADD operation specifying an object in (supposedly) inaccessible sub-tree. The returned error messages discloses the information when the queried object exists having the specified value. Attacker can use this flaw to guess values of RDN component by repeating the above process (CVE-2016-4992). References: - https://bugs.mageia.org/show_bug.cgi?id=19304 - https://lists.fedoraproject.org/archives/list/package-ann... - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4992 SRPMS: - 5/core/389-ds-base-1.3.4.14-1.mga5
