Описание
The acllas__handle_group_entry function in servers/plugins/acl/acllas.c in 389 Directory Server before 1.2.10 does not properly handled access control instructions (ACIs) that use certificate groups, which allows remote authenticated LDAP users with a certificate group to cause a denial of service (infinite loop and CPU consumption) by binding to the server.
Релиз | Статус | Примечание |
---|---|---|
devel | not-affected | 1.2.10.4-0ubuntu3 |
esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was not-affected [1.2.10.4-0ubuntu3]] |
hardy | DNE | |
lucid | DNE | |
natty | DNE | |
oneiric | DNE | |
precise | not-affected | 1.2.10.4-0ubuntu3 |
quantal | ignored | end of life |
raring | ignored | end of life |
saucy | ignored | end of life |
Показывать по
2.3 Low
CVSS2
Связанные уязвимости
The acllas__handle_group_entry function in servers/plugins/acl/acllas.c in 389 Directory Server before 1.2.10 does not properly handled access control instructions (ACIs) that use certificate groups, which allows remote authenticated LDAP users with a certificate group to cause a denial of service (infinite loop and CPU consumption) by binding to the server.
The acllas__handle_group_entry function in servers/plugins/acl/acllas.c in 389 Directory Server before 1.2.10 does not properly handled access control instructions (ACIs) that use certificate groups, which allows remote authenticated LDAP users with a certificate group to cause a denial of service (infinite loop and CPU consumption) by binding to the server.
The acllas__handle_group_entry function in servers/plugins/acl/acllas. ...
The acllas__handle_group_entry function in servers/plugins/acl/acllas.c in 389 Directory Server before 1.2.10 does not properly handled access control instructions (ACIs) that use certificate groups, which allows remote authenticated LDAP users with a certificate group to cause a denial of service (infinite loop and CPU consumption) by binding to the server.
ELSA-2012-0813: 389-ds-base security, bug fix, and enhancement update (LOW)
2.3 Low
CVSS2