Описание
/usr/libexec/openldap/generate-server-cert.sh in openldap-servers sets weak permissions for the TLS certificate, which allows local users to obtain the TLS certificate by leveraging a race condition between the creation of the certificate, and the chmod to protect it.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 5 | openldap | Will not fix | ||
| Red Hat Enterprise Linux 6 | openldap | Will not fix | ||
| Red Hat Enterprise Linux 7 | openldap | Will not fix |
Показывать по
Дополнительная информация
Статус:
EPSS
2.7 Low
CVSS3
1.9 Low
CVSS2
Связанные уязвимости
/usr/libexec/openldap/generate-server-cert.sh in openldap-servers sets weak permissions for the TLS certificate, which allows local users to obtain the TLS certificate by leveraging a race condition between the creation of the certificate, and the chmod to protect it.
/usr/libexec/openldap/generate-server-cert.sh in openldap-servers sets weak permissions for the TLS certificate, which allows local users to obtain the TLS certificate by leveraging a race condition between the creation of the certificate, and the chmod to protect it.
/usr/libexec/openldap/generate-server-cert.sh in openldap-servers sets ...
/usr/libexec/openldap/generate-server-cert.sh in openldap-servers sets weak permissions for the TLS certificate, which allows local users to obtain the TLS certificate by leveraging a race condition between the creation of the certificate, and the chmod to protect it.
EPSS
2.7 Low
CVSS3
1.9 Low
CVSS2