PT-2012-1067 · Red Hat+2 · 389-Ds-Base+7

Publicado

2012-06-20

·

Atualizado

2017-09-19

·

CVE-2012-2678

CVSS v2.0

2.1

Baixa

VetorAV:N/AC:H/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions 389 Directory Server versions prior to 1.2.11.6 389-ds-base-debuginfo versions 1.2.10.2 389-ds-base versions 1.2.10.2 389-ds-base-libs versions 1.2.10.2 389-ds-base-devel versions 1.2.10.2
Description The issue allows remote attackers to read plaintext passwords via the unhashed#user#password attribute after a LDAP user's password has been changed and before the server has been reset. Exploitation of the vulnerabilities can be carried out remotely by an attacker who has passed the authentication procedure, potentially leading to a breach of protected information confidentiality.
Recommendations For 389 Directory Server versions prior to 1.2.11.6, update to version 1.2.11.6 or later. For 389-ds-base-debuginfo versions 1.2.10.2, update to a version that is not affected by the vulnerability. For 389-ds-base versions 1.2.10.2, update to a version that is not affected by the vulnerability. For 389-ds-base-libs versions 1.2.10.2, update to a version that is not affected by the vulnerability. For 389-ds-base-devel versions 1.2.10.2, update to a version that is not affected by the vulnerability. As a temporary workaround, consider restricting access to the unhashed#user#password attribute until a patch is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-06132
BDU:2015-06133
BDU:2015-06134
BDU:2015-06135
BDU:2015-08859
BDU:2015-08860
BDU:2015-08861
BDU:2015-08862
CESA-2012_0997
CVE-2012-2678
HPSBUX02881
RHSA-2012:0997
RHSA-2012:1041
RHSA-2012_0997

Produtos afetados

389 Directory Server
389-Ds-Base
389-Ds-Base-Debuginfo
389-Ds-Base-Devel
389-Ds-Base-Libs
Centos
Hp-Ux
Red Hat