Описание
389 Directory Server 1.3.1.x, 1.3.2.x before 1.3.2.27, and 1.3.3.x before 1.3.3.9 stores "unhashed" passwords even when the nsslapd-unhashed-pw-switch option is set to off, which allows remote authenticated users to obtain sensitive information by reading the Changelog.
Релиз | Статус | Примечание |
---|---|---|
artful | not-affected | |
bionic | not-affected | |
cosmic | not-affected | |
devel | not-affected | |
disco | not-affected | |
esm-apps/bionic | not-affected | |
esm-apps/xenial | not-affected | |
esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was needed] |
lucid | DNE | |
precise | not-affected | 1.2.10.4-0ubuntu3.1 |
Показывать по
Ссылки на источники
EPSS
4 Medium
CVSS2
Связанные уязвимости
389 Directory Server 1.3.1.x, 1.3.2.x before 1.3.2.27, and 1.3.3.x before 1.3.3.9 stores "unhashed" passwords even when the nsslapd-unhashed-pw-switch option is set to off, which allows remote authenticated users to obtain sensitive information by reading the Changelog.
389 Directory Server 1.3.1.x, 1.3.2.x before 1.3.2.27, and 1.3.3.x before 1.3.3.9 stores "unhashed" passwords even when the nsslapd-unhashed-pw-switch option is set to off, which allows remote authenticated users to obtain sensitive information by reading the Changelog.
389 Directory Server 1.3.1.x, 1.3.2.x before 1.3.2.27, and 1.3.3.x bef ...
389 Directory Server 1.3.1.x, 1.3.2.x before 1.3.2.27, and 1.3.3.x before 1.3.3.9 stores "unhashed" passwords even when the nsslapd-unhashed-pw-switch option is set to off, which allows remote authenticated users to obtain sensitive information by reading the Changelog.
ELSA-2015-0416: 389-ds-base security, bug fix, and enhancement update (IMPORTANT)
EPSS
4 Medium
CVSS2