PT-2007-1045 · Dovecot+3 · Dovecot+3

Josh Bressers

·

Publicado

2007-11-13

·

Atualizado

2018-10-15

·

CVE-2007-5794

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: nss ldap versions prior to 258
Description: A race condition in nss ldap might send user data to the wrong process because of improper handling of the LDAP connection. This issue can lead to a breach of confidentiality of protected information and can be exploited remotely. The problem was originally reported in applications linked against the pthread library and fork after a call to nss ldap, such as Dovecot, where it caused the wrong mailboxes to be returned. Other applications might also be affected.
Recommendations: For versions prior to 258, update to version 258 or later to resolve the issue. As a temporary workaround, consider restricting the use of nss ldap in applications that fork after a call to nss ldap to minimize the risk of exploitation.

Correção

Race Condition

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-03680
BDU:2015-09612
CVE-2007-5794
DSA-1430-1
RHSA-2008:0389
RHSA-2008:0715
RHSA-2008_0389
RHSA-2008_0715

Produtos afetados

Dovecot
Red Hat
Nss Ldap
Thread