Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-4984

Опубликовано: 13 июн. 2016
Источник: redhat
CVSS3: 2.7
CVSS2: 1.9
EPSS Низкий

Описание

/usr/libexec/openldap/generate-server-cert.sh in openldap-servers sets weak permissions for the TLS certificate, which allows local users to obtain the TLS certificate by leveraging a race condition between the creation of the certificate, and the chmod to protect it.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5openldapWill not fix
Red Hat Enterprise Linux 6openldapWill not fix
Red Hat Enterprise Linux 7openldapWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-732
https://bugzilla.redhat.com/show_bug.cgi?id=1346120openldap-servers: /usr/libexec/openldap/generate-server-cert.sh create world readable password file

EPSS

Процентиль: 6%
0.00024
Низкий

2.7 Low

CVSS3

1.9 Low

CVSS2

Связанные уязвимости

CVSS3: 4.7
ubuntu
больше 8 лет назад

/usr/libexec/openldap/generate-server-cert.sh in openldap-servers sets weak permissions for the TLS certificate, which allows local users to obtain the TLS certificate by leveraging a race condition between the creation of the certificate, and the chmod to protect it.

CVSS3: 4.7
nvd
больше 8 лет назад

/usr/libexec/openldap/generate-server-cert.sh in openldap-servers sets weak permissions for the TLS certificate, which allows local users to obtain the TLS certificate by leveraging a race condition between the creation of the certificate, and the chmod to protect it.

CVSS3: 4.7
debian
больше 8 лет назад

/usr/libexec/openldap/generate-server-cert.sh in openldap-servers sets ...

CVSS3: 4.7
github
больше 3 лет назад

/usr/libexec/openldap/generate-server-cert.sh in openldap-servers sets weak permissions for the TLS certificate, which allows local users to obtain the TLS certificate by leveraging a race condition between the creation of the certificate, and the chmod to protect it.

EPSS

Процентиль: 6%
0.00024
Низкий

2.7 Low

CVSS3

1.9 Low

CVSS2