PT-2007-1045 · Dovecot+3 · Dovecot+3

Josh Bressers

·

Published

2007-11-13

·

Updated

2018-10-15

·

CVE-2007-5794

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: nss ldap versions prior to 258
Description: A race condition in nss ldap might send user data to the wrong process because of improper handling of the LDAP connection. This issue can lead to a breach of confidentiality of protected information and can be exploited remotely. The problem was originally reported in applications linked against the pthread library and fork after a call to nss ldap, such as Dovecot, where it caused the wrong mailboxes to be returned. Other applications might also be affected.
Recommendations: For versions prior to 258, update to version 258 or later to resolve the issue. As a temporary workaround, consider restricting the use of nss ldap in applications that fork after a call to nss ldap to minimize the risk of exploitation.

Fix

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-03680
BDU:2015-09612
CVE-2007-5794
DSA-1430-1
RHSA-2008:0389
RHSA-2008:0715
RHSA-2008_0389
RHSA-2008_0715

Affected Products

Dovecot
Red Hat
Nss Ldap
Thread