Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-15135

Опубликовано: 22 янв. 2018
Источник: redhat
CVSS3: 4.6
EPSS Низкий

Описание

It was found that 389-ds-base since 1.3.6.1 up to and including 1.4.0.3 did not always handle internal hash comparison operations correctly during the authentication process. A remote, unauthenticated attacker could potentially use this flaw to bypass the authentication process under very rare and specific circumstances.

It was found that 389-ds-base did not always handle internal hash comparison operations correctly during the authentication process. A remote, unauthenticated attacker could potentially use this flaw to bypass the authentication process under very rare and specific circumstances.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-287
https://bugzilla.redhat.com/show_bug.cgi?id=1525628389-ds-base: Authentication bypass due to lack of size check in slapi_ct_memcmp function in ch_malloc.c

EPSS

Процентиль: 86%
0.02785
Низкий

4.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
почти 8 лет назад

It was found that 389-ds-base since 1.3.6.1 up to and including 1.4.0.3 did not always handle internal hash comparison operations correctly during the authentication process. A remote, unauthenticated attacker could potentially use this flaw to bypass the authentication process under very rare and specific circumstances.

CVSS3: 8.1
nvd
почти 8 лет назад

It was found that 389-ds-base since 1.3.6.1 up to and including 1.4.0.3 did not always handle internal hash comparison operations correctly during the authentication process. A remote, unauthenticated attacker could potentially use this flaw to bypass the authentication process under very rare and specific circumstances.

CVSS3: 8.1
debian
почти 8 лет назад

It was found that 389-ds-base since 1.3.6.1 up to and including 1.4.0. ...

CVSS3: 8.1
github
больше 3 лет назад

It was found that 389-ds-base since 1.3.6.1 up to and including 1.4.0.3 did not always handle internal hash comparison operations correctly during the authentication process. A remote, unauthenticated attacker could potentially use this flaw to bypass the authentication process under very rare and specific circumstances.

CVSS3: 5.9
fstec
почти 8 лет назад

Уязвимость службы каталогов уровня предприятия 389 Directory Server, связанная с неправильной аутентификацией, позволяющая нарушителю получить доступ к конфиденциальным данным

EPSS

Процентиль: 86%
0.02785
Низкий

4.6 Medium

CVSS3