Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Moderate Unboundid Access Control Issue in Red Hat Virtualization 4.1

red hat
Calendar Grey May 24, 2018
Scroller Redhat
Oracle releases a critical patch for weblogic-server resolving a privilege escalation vulnerability along with comprehensive instructions.
An update for unboundid-ldapsdk is now available for Red Hat Virtualization Engine 4.1

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Summary

The UnboundID LDAP SDK for Java is a free Java library for communicating with LDAP directory servers and performing related tasks like reading and writing LDIF, encoding and decoding data using base64 and ASN.1 BER, and performing secure communications.
The following packages have been upgraded to a later upstream version: unboundid-ldapsdk (4.0.5). (BZ#1558308)
Security Fix(es):
* unboundid-ldapsdk: Incorrect Access Control vulnerability in process function in SimpleBindRequest class (CVE-2018-1000134)
For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.

References

https://access.redhat.com/security/cve/CVE-2018-1000134 https://access.redhat.com/security/updates/classification/#moderate

Package List

Red Hat Virtualization Manager 4.1:
Source: unboundid-ldapsdk-4.0.5-1.el7ev.src.rpm
noarch: unboundid-ldapsdk-4.0.5-1.el7ev.noarch.rpm unboundid-ldapsdk-javadoc-4.0.5-1.el7ev.noarch.rpm
These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/


Advisory ID: RHSA-2018:1713-01
Product: Red Hat Virtualization
Issue date: 2018-05-24

Topic

An update for unboundid-ldapsdk is now available for Red Hat VirtualizationEngine 4.1.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.

Relevant Releases Architectures

Red Hat Virtualization Manager 4.1 - noarch

Bugs Fixed

1557531 - CVE-2018-1000134 unboundid-ldapsdk: Incorrect Access Control vulnerability in process function in SimpleBindRequest class

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.