Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

Debian 7 DLA-1180-1 moderate: Libspring-Ldap-Java Authentication Issue

debian lts
Calendar Grey November 19, 2017
Dist Debian Esm H88
Enhance libspring-ldap-java to resolve authentication vulnerabilities related to random passwords. Security notice DLA-1180-1.
Tobias Schneider discovered that Spring-LDAP would allow authentication with an arbitrary password when the username is correct, no additional attributes are bound and when using L...

Summary

For Debian 7 "Wheezy", these problems have been fixed in version
1.3.1.RELEASE-4+deb7u1.

We recommend that you upgrade your libspring-ldap-java packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Package: libspring-ldap-java
Version: 1.3.1.RELEASE-4+deb7u1
CVE ID: CVE-2017-8028

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here