CVE-2012-0833
The acllas__handle_group_entry function in servers/plugins/acl/acllas.c in 389 Directory Server before 1.2.10 does not properly handled access control instructions (ACIs) that use certificate groups, which allows remote authenticated LDAP users with a…
Does this matter?
Lower severity and a low EPSS score (0.90%). Track it; it rarely justifies an emergency change on its own.
Description
The acllas__handle_group_entry function in servers/plugins/acl/acllas.c in 389 Directory Server before 1.2.10 does not properly handled access control instructions (ACIs) that use certificate groups, which allows remote authenticated LDAP users with a certificate group to cause a denial of service (infinite loop and CPU consumption) by binding to the server.
- CVSS 2.0
- 2.3 LOWAV:A/AC:M/Au:S/C:N/I:N/A:P
- EPSS
- 0.90% probability · 58th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- fedoraproject/389 directory server
- Source
- secalert@redhat.com
References
- http://rhn.redhat.com/errata/RHSA-2012-0813.html
- http://secunia.com/advisories/48035Vendor Advisory
- http://secunia.com/advisories/49562Vendor Advisory
- https://fedorahosted.org/389/changeset/1bbbb3e5049c1aa0650546efab87ed2f1ea59637/389-ds-baseExploit, Patch
- https://fedorahosted.org/389/ticket/162
- http://rhn.redhat.com/errata/RHSA-2012-0813.html
- http://secunia.com/advisories/48035Vendor Advisory
- http://secunia.com/advisories/49562Vendor Advisory
- https://fedorahosted.org/389/changeset/1bbbb3e5049c1aa0650546efab87ed2f1ea59637/389-ds-baseExploit, Patch
- https://fedorahosted.org/389/ticket/162
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.