Vulnerability CVE-2012-2678


Published: 2012-07-03   Modified: 2012-07-04

Description:
389 Directory Server before 1.2.11.6 (aka Red Hat Directory Server before 8.2.10-3), after the password for a LDAP user has been changed and before the server has been reset, allows remote attackers to read the plaintext password via the unhashed#user#password attribute.

Type:

CWE-310

(Cryptographic Issues)

CVSS2 => (AV:L/AC:H/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
1.2/10
2.9/10
1.9/10
Exploit range
Attack complexity
Authentication
Local
High
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
Redhat -> Directory server 
Fedoraproject -> 389 directory server 

 References:
https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03772083
https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03772083
http://www.securityfocus.com/bid/54153
http://secunia.com/advisories/49734
http://rhn.redhat.com/errata/RHSA-2012-1041.html
http://rhn.redhat.com/errata/RHSA-2012-0997.html
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:19353
http://osvdb.org/83336
http://directory.fedoraproject.org/wiki/Release_Notes

Copyright 2024, cxsecurity.com

 

Back to Top