Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Mageia 7: MGASA-2019-0411 High: 389-ds-base LDAP Denial of Service

mageia
Calendar Grey December 25, 2019
Dist Mageia Esm H88
The most recent Mageia release resolves significant security flaws in 389-ds-base concerning LDAP processing and unencrypted passwords.
he updated packages fix security vulnerabilities and a packaging problem: An out-of-bounds memory read flaw was found in the way 389-ds-base handled certain LDAP search filters, a...

Summary

he updated packages fix security vulnerabilities and a packaging problem:
An out-of-bounds memory read flaw was found in the way 389-ds-base handled certain LDAP search filters, affecting all versions including 1.4.x. A remote, unauthenticated attacker could potentially use this flaw to make ns-slapd crash via a specially crafted LDAP request, thus resulting in denial of service. (CVE-2018-1054)
389-ds-base before versions 1.3.8.5, 1.4.0.12 is vulnerable to a Cleartext Storage of Sensitive Information. By default, when the Replica and/or retroChangeLog plugins are enabled, 389-ds-base stores passwords in plaintext format in their respective changelog files. An attacker with sufficiently high privileges, such as root or Directory Manager, can query these files in order to retrieve plaintext passwords. (CVE-2018-10871)
In 389-ds-base up to version 1.4.1.2, requests are handled by workersthreads. Each sockets will be waited by the worker for at most 'ioblocktimeout' seconds. However th...

Read the Full Advisory

References

- https://bugs.mageia.org/show_bug.cgi?id=25824

- https://bugs.mageia.org/show_bug.cgi?id=25709

- http://lists.suse.com/pipermail/sle-security-updates/2019-August/005817.html

- - https://www.cve.org/CVERecord?id=CVE-2018-1054

- https://www.cve.org/CVERecord?id=CVE-2018-10871

- https://www.cve.org/CVERecord?id=CVE-2019-3883

- https://www.cve.org/CVERecord?id=CVE-2019-14824

Resolution

SRPMS

- 7/core/389-ds-base-1.4.0.26-1.1.mga7

Publication date: 25 Dec 2019
URL: https://advisories.mageia.org/MGASA-2019-0411.html
Type: security
CVE: CVE-2018-1054, CVE-2018-10871, CVE-2019-3883, CVE-2019-14824

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here