Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2015-0628

Опубликовано: 05 мар. 2015
Источник: oracle-oval
Платформа: Oracle Linux 6

Описание

ELSA-2015-0628: 389-ds-base security, bug fix, and enhancement update (IMPORTANT)

[1.2.11.15-50]

  • Release 1.2.11.15-50
  • Resolves: #1179099 - Problem with single value attribute MMR replication (DS 47915, DS 569)

[1.2.11.15-49]

  • Release 1.2.11.15-49
  • Resolves: #1180629 - CVE-2014-8105: information disclosure through 'cn=changelog' subtree
  • Resolves: #1179099 - Problem with single value attribute MMR replication (DS 47915)
  • Resolves: #1179595 - default nsslapd-sasl-max-buffer-size should be 2MB (DS 47457)
  • Resolves: #1179100 - ACI's are replaced by 'ACI_ALL' after editing goup of ACI's including invalid one (DS 47953)

Обновленные пакеты

Oracle Linux 6

Oracle Linux x86_64

389-ds-base

1.2.11.15-50.el6_6

389-ds-base-devel

1.2.11.15-50.el6_6

389-ds-base-libs

1.2.11.15-50.el6_6

Oracle Linux i686

389-ds-base

1.2.11.15-50.el6_6

389-ds-base-devel

1.2.11.15-50.el6_6

389-ds-base-libs

1.2.11.15-50.el6_6

Связанные CVE

Связанные уязвимости

ubuntu
больше 10 лет назад

389 Directory Server before 1.3.2.27 and 1.3.3.x before 1.3.3.9 does not properly restrict access to the "cn=changelog" LDAP sub-tree, which allows remote attackers to obtain sensitive information from the changelog via unspecified vectors.

redhat
больше 10 лет назад

389 Directory Server before 1.3.2.27 and 1.3.3.x before 1.3.3.9 does not properly restrict access to the "cn=changelog" LDAP sub-tree, which allows remote attackers to obtain sensitive information from the changelog via unspecified vectors.

nvd
больше 10 лет назад

389 Directory Server before 1.3.2.27 and 1.3.3.x before 1.3.3.9 does not properly restrict access to the "cn=changelog" LDAP sub-tree, which allows remote attackers to obtain sensitive information from the changelog via unspecified vectors.

debian
больше 10 лет назад

389 Directory Server before 1.3.2.27 and 1.3.3.x before 1.3.3.9 does n ...

github
больше 3 лет назад

389 Directory Server before 1.3.2.27 and 1.3.3.x before 1.3.3.9 does not properly restrict access to the "cn=changelog" LDAP sub-tree, which allows remote attackers to obtain sensitive information from the changelog via unspecified vectors.