PT-2014-1864 · Red Hat+1 · 389-Ds-Base+2

Rv3

·

Published

2014-03-13

·

Updated

2023-02-13

·

CVE-2014-0132

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions 389-ds-base versions 1.2.11.15 through 1.2.11.25
Description The issue allows remote authenticated users to connect as an arbitrary user and gain privileges via the authzid parameter in a SASL/GSSAPI bind. This can lead to a violation of confidentiality, integrity, and availability of protected information. The exploitation can be carried out remotely by an attacker who has passed the authentication procedure.
Recommendations For versions 1.2.11.15 through 1.2.11.25, update to version 1.2.11.26 or later to resolve the issue. As a temporary workaround, consider restricting access to the SASL/GSSAPI bind functionality until a patch is available. Avoid using the authzid parameter in the affected bind operation until the issue is resolved.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-07164
BDU:2015-07165
BDU:2015-07166
BDU:2015-07167
BDU:2015-09092
BDU:2015-09093
BDU:2015-09094
BDU:2015-09095
CESA-2014_0292
CVE-2014-0132
MGASA-2014-0145
RHSA-2014:0292
RHSA-2014_0292

Affected Products

389-Ds-Base
Centos
Red Hat