Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-5405

Опубликовано: 26 окт. 2016
Источник: redhat
CVSS3: 6.8
CVSS2: 2.6

Описание

389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server 6 through 7, and Red Hat Enterprise Linux Workstation 6 through 7 allows remote attackers to obtain user passwords.

It was found that 389 Directory Server was vulnerable to a remote password disclosure via timing attack. A remote attacker could possibly use this flaw to retrieve directory server password after many tries.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Directory Server 8redhat-ds-baseWill not fix
Red Hat Enterprise Linux 6389-ds-baseFixedRHSA-2016:276515.11.2016
Red Hat Enterprise Linux 7389-ds-baseFixedRHSA-2016:259403.11.2016

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-385
https://bugzilla.redhat.com/show_bug.cgi?id=1358865389-ds-base: Password verification vulnerable to timing attack

6.8 Medium

CVSS3

2.6 Low

CVSS2

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 8 лет назад

389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server 6 through 7, and Red Hat Enterprise Linux Workstation 6 through 7 allows remote attackers to obtain user passwords.

CVSS3: 9.8
nvd
больше 8 лет назад

389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server 6 through 7, and Red Hat Enterprise Linux Workstation 6 through 7 allows remote attackers to obtain user passwords.

CVSS3: 9.8
debian
больше 8 лет назад

389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, ...

CVSS3: 9.8
github
больше 3 лет назад

389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server 6 through 7, and Red Hat Enterprise Linux Workstation 6 through 7 allows remote attackers to obtain user passwords.

oracle-oval
почти 9 лет назад

ELSA-2016-2765: 389-ds-base security, bug fix, and enhancement update (MODERATE)

6.8 Medium

CVSS3

2.6 Low

CVSS2