The do_search function in ldap/servers/slapd/search.c in 389 Directory Server 1.2.x before 1.2.11.20 and 1.3.x before 1.3.0.5 does not properly restrict access to entries when the nsslapd-allow-anonymous-access configuration is set to rootdse and the BASE search scope is used, which allows remote attackers to obtain sensitive information outside of the rootDSE via a crafted LDAP search.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
21 Nov 2024, 01:50
Type | Values Removed | Values Added |
---|---|---|
References | () http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101323.html - | |
References | () http://rhn.redhat.com/errata/RHSA-2013-0742.html - | |
References | () https://bugzilla.redhat.com/show_bug.cgi?id=928105 - | |
References | () https://fedorahosted.org/389/ticket/47308 - | |
References | () https://fedorahosted.org/freeipa/ticket/3540 - Vendor Advisory | |
References | () https://git.fedorahosted.org/cgit/389/ds.git/commit/?h=389-ds-base-1.2.11&id=5a18c828533a670e7143327893f8171a19062286 - |
Information
Published : 2013-05-13 23:55
Updated : 2024-11-21 01:50
NVD link : CVE-2013-1897
Mitre link : CVE-2013-1897
CVE.ORG link : CVE-2013-1897
JSON object : View
Products Affected
fedoraproject
- 389_directory_server
CWE
CWE-264
Permissions, Privileges, and Access Controls