Описание
A flaw was found in 389 Directory Server. A type confusion in the SSO token extended operation handler causes partial stack address information to be disclosed in LDAP responses to authenticated users.
Отчет
This Moderate impact flaw in 389 Directory Server allows an authenticated, non-administrator user to obtain partial stack address information. The SSO token feature, which is enabled by default in Red Hat Directory Server, leaks the lower 32 bits of a stack address in LDAP extended operation responses, reducing Address Space Layout Randomization (ASLR) entropy but not leading to a full bypass.
Меры по смягчению последствий
Option 1 (Recommended): Disable the SSO token feature entirely: dsconf config replace nsslapd-enable-ldapssotoken=off. This prevents the vulnerable code path from being reached but disables SSO token functionality for all users. Option 2: Restrict network access to LDAP ports (389/636) to trusted networks via firewall rules. Note: Removing the SSO token secret from configuration does not mitigate the vulnerability — the server auto-generates a new secret at startup.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Directory Server 11 | redhat-ds:11/389-ds-base | Not affected | ||
| Red Hat Directory Server 12 | redhat-ds:12/389-ds-base | Fix deferred | ||
| Red Hat Directory Server 13 | 389-ds-base | Fix deferred | ||
| Red Hat Enterprise Linux 10 | 389-ds-base | Fix deferred | ||
| Red Hat Enterprise Linux 6 | 389-ds-base | Not affected | ||
| Red Hat Enterprise Linux 7 | 389-ds-base | Not affected | ||
| Red Hat Enterprise Linux 8 | 389-ds-base | Not affected | ||
| Red Hat Enterprise Linux 9 | 389-ds-base | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
4.3 Medium
CVSS3
Связанные уязвимости
A flaw was found in 389 Directory Server. A type confusion in the SSO token extended operation handler causes partial stack address information to be disclosed in LDAP responses to authenticated users.
A flaw was found in 389 Directory Server. A type confusion in the SSO token extended operation handler causes partial stack address information to be disclosed in LDAP responses to authenticated users.
A flaw was found in 389 Directory Server. A type confusion in the SSO ...
A flaw was found in 389 Directory Server. A type confusion in the SSO token extended operation handler causes partial stack address information to be disclosed in LDAP responses to authenticated users.
EPSS
4.3 Medium
CVSS3