Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
After installing this update, the 389 server service will be restarted
automatically.
389 Directory Server is an LDAP version 3 (LDAPv3) compliant server. The
base packages include the Lightweight Directory Access Protocol (LDAP)
server and command-line utilities for server administration.
The following packages have been upgraded to a newer upstream version:
389-ds-base (1.3.5.10). (BZ#1270020)
Security Fix(es):
* It was found that 389 Directory Server was vulnerable to a flaw in which
the default ACI (Access Control Instructions) could be read by an anonymous
user. This could lead to leakage of sensitive information. (CVE-2016-5416)
* An information disclosure flaw was found in 389 Directory Server. A user
with no access to objects in certain LDAP sub-tree could send LDAP ADD
operations with a specific object name. The error message returned to the
user was different based on whether the target object existed or not.
(CVE-2016-4992)
* It was found that 389 Directory Server was vulnerable to a remote
password disclosure via timing attack. A remote attacker could possibly use
this flaw to retrieve directory server password after many tries.
(CVE-2016-5405)
The CVE-2016-5416 issue was discovered by Viktor Ashirov (Red Hat); the
CVE-2016-4992 issue was discovered by Petr Spacek (Red Hat) and Martin
Basti (Red Hat); and the CVE-2016-5405 issue was discovered by William
Brown (Red Hat).
Additional Changes:
For detailed information on changes in this release, see the Red Hat
Enterprise Linux 7.3 Release Notes linked from the References section.
https://access.redhat.com/security/cve/CVE-2016-4992 https://access.redhat.com/security/cve/CVE-2016-5405 https://access.redhat.com/security/cve/CVE-2016-5416 https://access.redhat.com/security/updates/classification#moderate https://docs.redhat.com/en/documentation/Red_Hat_Enterprise_Linux/7/html/7.3_Release_Notes/index.html
Red Hat Enterprise Linux Client Optional (v. 7):
Source:
389-ds-base-1.3.5.10-11.el7.src.rpm
x86_64:
389-ds-base-1.3.5.10-11.el7.x86_64.rpm
389-ds-base-debuginfo-1.3.5.10-11.el7.x86_64.rpm
389-ds-base-devel-1.3.5.10-11.el7.x86_64.rpm
389-ds-base-libs-1.3.5.10-11.el7.x86_64.rpm
389-ds-base-snmp-1.3.5.10-11.el7.x86_64.rpm
Red Hat Enterprise Linux ComputeNode Optional (v. 7):
Source:
389-ds-base-1.3.5.10-11.el7.src.rpm
x86_64:
389-ds-base-1.3.5.10-11.el7.x86_64.rpm
389-ds-base-debuginfo-1.3.5.10-11.el7.x86_64.rpm
389-ds-base-devel-1.3.5.10-11.el7.x86_64.rpm
389-ds-base-libs-1.3.5.10-11.el7.x86_64.rpm
389-ds-base-snmp-1.3.5.10-11.el7.x86_64.rpm
Red Hat Enterprise Linux Server (v. 7):
Source:
389-ds-base-1.3.5.10-11.el7.src.rpm
aarch64:
389-ds-base-1.3.5.10-11.el7.aarch64.rpm
389-ds-base-debuginfo-1.3.5.10-11.el7.aarch64.rpm
389-ds-base-libs-1.3.5.10-11.el7.aarch64.rpm
ppc64le:
389-ds-base-1.3.5.10-11.el7.ppc64le.rpm
389-ds-base-debuginfo-1.3.5.10-11.el7.ppc64le.rpm
389-ds-base-libs-1.3.5.10-11.el7.ppc64le.rpm
x86_64:
389-ds-base-1.3.5.10-11.el7.x86_64.rpm
389-ds-base-debuginfo-1.3.5.10-11.el7.x86_64.rpm
389-ds-base-libs-1.3.5.10-11.el7.x86_64.rpm
Red Hat Enterprise Linux Server Optional (v. 7):
aarch64:
389-ds-base-debuginfo-1.3.5.10-11.el7.aarch64.rpm
Read the Full Advisory
An update for 389-ds-base is now available for Red Hat Enterprise Linux 7.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.
Red Hat Enterprise Linux Client Optional (v. 7) - x86_64
Red Hat Enterprise Linux ComputeNode Optional (v. 7) - x86_64
Red Hat Enterprise Linux Server (v. 7) - aarch64, ppc64le, x86_64
Red Hat Enterprise Linux Server Optional (v. 7) - aarch64, ppc64le, x86_64
Red Hat Enterprise Linux Workstation (v. 7) - x86_64
Red Hat Enterprise Linux Workstation Optional (v. 7) - x86_64
190862 - [RFE] Default password syntax settings don't work with fine-grained policies
1018944 - [RFE] Enhance password change tracking
1143066 - [RFE] The dirsrv user/group should be created in rpm %pre, and ideally with fixed uid/gid
1160902 - search, matching rules and filter error "unsupported type 0xA9"
1196282 - substring index with nssubstrbegin: 1 is not being used with filters like (attr=x*)
1209128 - [RFE] Add a utility to get the status of Directory Server instances
1210842 - Add PIDFile option to systemd service file
1223510 - nsslapd-maxbersize should be ignored in replication
1229799 - 389-ds-base: ldclt-bin killed by SIGSEGV
1249908 - No validation check for the value for nsslapd-db-locks.
1254887 - No man page entry for - option '-u' of dbgen.pl for adding group entries with uniquemembers1255557 - db2index creates index entry from deleted records
1257568 - /usr/lib64/dirsrv/libnunc-stans.so is owned by both -libs and -devel
1258610 - total update request must not be lost
1258611 - dna plugin needs to handle binddn groups for authorization
1259950 - Add config setting to MemberOf Plugin to add required objectclass got memberOf attribute
1266510 - Linked Attributes plug-in - wrong behaviour when adding valid and broken links
1266532 - Linked Attributes plug-in - won't update links after MODRDN operation
1267750 - pagedresults - when timed out, search results could have been already freed.
Get the latest Linux and open source security news straight to your inbox.