PT-2012-2894 · Red Hat+1 · 389 Directory Server+2

Rich Megginson

+1

·

Published

2012-06-19

·

Updated

2012-07-17

·

CVE-2012-0833

CVSS v2.0

2.3

Low

VectorAV:A/AC:M/Au:S/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions 389 Directory Server versions prior to 1.2.10
Description The issue arises from the improper handling of access control instructions (ACIs) that utilize certificate groups by the acllas handle group entry function. This allows remote authenticated LDAP users with a certificate group to cause a denial of service, characterized by an infinite loop and excessive CPU consumption, by binding to the server.
Recommendations For versions prior to 1.2.10, update to version 1.2.10 or later to resolve the issue. As a temporary workaround, consider restricting access to the acllas handle group entry function in the servers/plugins/acl/acllas.c file until a patch is applied.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CESA-2012_0813
CVE-2012-0833
RHSA-2012:0813
RHSA-2012_0813
RHSA-2013:0549

Affected Products

389 Directory Server
Centos
Red Hat