PT-2012-2894 · Red Hat+1 · 389 Directory Server+2

Rich Megginson

+1

·

Publicado

2012-06-19

·

Atualizado

2012-07-17

·

CVE-2012-0833

CVSS v2.0

2.3

Baixa

VetorAV:A/AC:M/Au:S/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions 389 Directory Server versions prior to 1.2.10
Description The issue arises from the improper handling of access control instructions (ACIs) that utilize certificate groups by the acllas handle group entry function. This allows remote authenticated LDAP users with a certificate group to cause a denial of service, characterized by an infinite loop and excessive CPU consumption, by binding to the server.
Recommendations For versions prior to 1.2.10, update to version 1.2.10 or later to resolve the issue. As a temporary workaround, consider restricting access to the acllas handle group entry function in the servers/plugins/acl/acllas.c file until a patch is applied.

Exploit

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CESA-2012_0813
CVE-2012-0833
RHSA-2012:0813
RHSA-2012_0813
RHSA-2013:0549

Produtos afetados

389 Directory Server
Centos
Red Hat