Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-35518

Опубликовано: 26 мар. 2021
Источник: debian

Описание

When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be used by an unauthenticated attacker to check the existence of an entry in the LDAP database.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
389-ds-basefixed1.4.4.10-1package
389-ds-basenot-affectedbusterpackage
389-ds-basenot-affectedstretchpackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=1905565

  • https://github.com/389ds/389-ds-base/issues/4480

  • https://github.com/389ds/389-ds-base/commit/cc0f69283abc082488824702dae485b8eae938bc (master)

  • https://github.com/389ds/389-ds-base/commit/38b97faef8a6421a7a638ecdbf0b341e2b3f9ab3 (1.4.4.10)

  • Introduced as side-effect of https://github.com/389ds/389-ds-base/issues/2535

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 5 лет назад

When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be used by an unauthenticated attacker to check the existence of an entry in the LDAP database.

CVSS3: 5.3
redhat
около 5 лет назад

When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be used by an unauthenticated attacker to check the existence of an entry in the LDAP database.

CVSS3: 5.3
nvd
почти 5 лет назад

When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be used by an unauthenticated attacker to check the existence of an entry in the LDAP database.

suse-cvrf
почти 5 лет назад

Security update for 389-ds

suse-cvrf
почти 5 лет назад

Security update for 389-ds