PT-2014-1864 · Red Hat+1 · 389-Ds-Base+2
Rv3
·
Published
2014-03-13
·
Updated
2023-02-13
·
CVE-2014-0132
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
389-ds-base versions 1.2.11.15 through 1.2.11.25
Description
The issue allows remote authenticated users to connect as an arbitrary user and gain privileges via the
authzid parameter in a SASL/GSSAPI bind. This can lead to a violation of confidentiality, integrity, and availability of protected information. The exploitation can be carried out remotely by an attacker who has passed the authentication procedure.Recommendations
For versions 1.2.11.15 through 1.2.11.25, update to version 1.2.11.26 or later to resolve the issue. As a temporary workaround, consider restricting access to the SASL/GSSAPI bind functionality until a patch is available. Avoid using the
authzid parameter in the affected bind operation until the issue is resolved.Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
389-Ds-Base
Centos
Red Hat