Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 464
Alerts This Week
Warning Icon 1 464

Red Hat: RHSA-2016-2594-02 Moderate: 389-ds-base Security Update

red hat
Calendar Grey November 3, 2016
Scroller Redhat
Important security patch released for CentOS 7 fixing various vulnerabilities in httpd software package. Discover the details today!
An update for 389-ds-base is now available for Red Hat Enterprise Linux 7

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

After installing this update, the 389 server service will be restarted automatically.

Summary

389 Directory Server is an LDAP version 3 (LDAPv3) compliant server. The base packages include the Lightweight Directory Access Protocol (LDAP) server and command-line utilities for server administration.
The following packages have been upgraded to a newer upstream version: 389-ds-base (1.3.5.10). (BZ#1270020)
Security Fix(es):
* It was found that 389 Directory Server was vulnerable to a flaw in which the default ACI (Access Control Instructions) could be read by an anonymous user. This could lead to leakage of sensitive information. (CVE-2016-5416)
* An information disclosure flaw was found in 389 Directory Server. A user with no access to objects in certain LDAP sub-tree could send LDAP ADD operations with a specific object name. The error message returned to the user was different based on whether the target object existed or not. (CVE-2016-4992)
* It was found that 389 Directory Server was vulnerable to a remote password disclosure via timing attack. A remote attacker could possibly use this flaw to retrieve directory server password after many tries. (CVE-2016-5405)
The CVE-2016-5416 issue was discovered by Viktor Ashirov (Red Hat); the CVE-2016-4992 issue was discovered by Petr Spacek (Red Hat) and Martin Basti (Red Hat); and the CVE-2016-5405 issue was discovered by William Brown (Red Hat).
Additional Changes:
For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.3 Release Notes linked from the References section.

References

https://access.redhat.com/security/cve/CVE-2016-4992 https://access.redhat.com/security/cve/CVE-2016-5405 https://access.redhat.com/security/cve/CVE-2016-5416 https://access.redhat.com/security/updates/classification#moderate https://docs.redhat.com/en/documentation/Red_Hat_Enterprise_Linux/7/html/7.3_Release_Notes/index.html

Package List

Red Hat Enterprise Linux Client Optional (v. 7):
Source: 389-ds-base-1.3.5.10-11.el7.src.rpm
x86_64: 389-ds-base-1.3.5.10-11.el7.x86_64.rpm 389-ds-base-debuginfo-1.3.5.10-11.el7.x86_64.rpm 389-ds-base-devel-1.3.5.10-11.el7.x86_64.rpm 389-ds-base-libs-1.3.5.10-11.el7.x86_64.rpm 389-ds-base-snmp-1.3.5.10-11.el7.x86_64.rpm
Red Hat Enterprise Linux ComputeNode Optional (v. 7):
Source: 389-ds-base-1.3.5.10-11.el7.src.rpm
x86_64: 389-ds-base-1.3.5.10-11.el7.x86_64.rpm 389-ds-base-debuginfo-1.3.5.10-11.el7.x86_64.rpm 389-ds-base-devel-1.3.5.10-11.el7.x86_64.rpm 389-ds-base-libs-1.3.5.10-11.el7.x86_64.rpm 389-ds-base-snmp-1.3.5.10-11.el7.x86_64.rpm
Red Hat Enterprise Linux Server (v. 7):
Source: 389-ds-base-1.3.5.10-11.el7.src.rpm
aarch64: 389-ds-base-1.3.5.10-11.el7.aarch64.rpm 389-ds-base-debuginfo-1.3.5.10-11.el7.aarch64.rpm 389-ds-base-libs-1.3.5.10-11.el7.aarch64.rpm
ppc64le: 389-ds-base-1.3.5.10-11.el7.ppc64le.rpm 389-ds-base-debuginfo-1.3.5.10-11.el7.ppc64le.rpm 389-ds-base-libs-1.3.5.10-11.el7.ppc64le.rpm
x86_64: 389-ds-base-1.3.5.10-11.el7.x86_64.rpm 389-ds-base-debuginfo-1.3.5.10-11.el7.x86_64.rpm 389-ds-base-libs-1.3.5.10-11.el7.x86_64.rpm
Red Hat Enterprise Linux Server Optional (v. 7):
aarch64: 389-ds-base-debuginfo-1.3.5.10-11.el7.aarch64.rpm

Read the Full Advisory


Advisory ID: RHSA-2016:2594-02
Product: Red Hat Enterprise Linux
Issue date: 2016-11-03

Topic

An update for 389-ds-base is now available for Red Hat Enterprise Linux 7.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.

Relevant Releases Architectures

Red Hat Enterprise Linux Client Optional (v. 7) - x86_64

Red Hat Enterprise Linux ComputeNode Optional (v. 7) - x86_64

Red Hat Enterprise Linux Server (v. 7) - aarch64, ppc64le, x86_64

Red Hat Enterprise Linux Server Optional (v. 7) - aarch64, ppc64le, x86_64

Red Hat Enterprise Linux Workstation (v. 7) - x86_64

Red Hat Enterprise Linux Workstation Optional (v. 7) - x86_64

Bugs Fixed

190862 - [RFE] Default password syntax settings don't work with fine-grained policies

1018944 - [RFE] Enhance password change tracking

1143066 - [RFE] The dirsrv user/group should be created in rpm %pre, and ideally with fixed uid/gid

1160902 - search, matching rules and filter error "unsupported type 0xA9"

1196282 - substring index with nssubstrbegin: 1 is not being used with filters like (attr=x*)

1209128 - [RFE] Add a utility to get the status of Directory Server instances

1210842 - Add PIDFile option to systemd service file

1223510 - nsslapd-maxbersize should be ignored in replication

1229799 - 389-ds-base: ldclt-bin killed by SIGSEGV

1249908 - No validation check for the value for nsslapd-db-locks.

1254887 - No man page entry for - option '-u' of dbgen.pl for adding group entries with uniquemembers1255557 - db2index creates index entry from deleted records

1257568 - /usr/lib64/dirsrv/libnunc-stans.so is owned by both -libs and -devel

1258610 - total update request must not be lost

1258611 - dna plugin needs to handle binddn groups for authorization

1259950 - Add config setting to MemberOf Plugin to add required objectclass got memberOf attribute

1266510 - Linked Attributes plug-in - wrong behaviour when adding valid and broken links

1266532 - Linked Attributes plug-in - won't update links after MODRDN operation

1267750 - pagedresults - when timed out, search results could have been already freed.

Read the Full Advisory

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.