VulnerabilityModified
CVE-2012-4450
389 Directory Server 1.2.10 does not properly update the ACL when a DN entry is moved by a modrdn operation, which allows remote authenticated users with certain permissions to bypass ACL restrictions and access the DN entry.
MEDIUM 6.0EPSS 1.86%
Does this matter?
Lower severity and a low EPSS score (1.86%). Track it; it rarely justifies an emergency change on its own.
Description
389 Directory Server 1.2.10 does not properly update the ACL when a DN entry is moved by a modrdn operation, which allows remote authenticated users with certain permissions to bypass ACL restrictions and access the DN entry.
- CVSS 2.0
- 6.0 MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
- EPSS
- 1.86% probability · 78th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- fedoraproject/389 directory server
- Source
- secalert@redhat.com
References
- http://git.fedorahosted.org/cgit/389/ds.git/commit/?id=5beb93d42efb807838c09c5fab898876876f8d09Patch, Vendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0503.html
- http://secunia.com/advisories/50713Vendor Advisory
- http://www.openwall.com/lists/oss-security/2012/09/26/3
- http://www.openwall.com/lists/oss-security/2012/09/26/5
- http://www.securityfocus.com/bid/55690
- https://bugzilla.redhat.com/show_bug.cgi?id=860772
- https://fedorahosted.org/389/ticket/340
- http://git.fedorahosted.org/cgit/389/ds.git/commit/?id=5beb93d42efb807838c09c5fab898876876f8d09Patch, Vendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0503.html
- http://secunia.com/advisories/50713Vendor Advisory
- http://www.openwall.com/lists/oss-security/2012/09/26/3
- http://www.openwall.com/lists/oss-security/2012/09/26/5
- http://www.securityfocus.com/bid/55690
- https://bugzilla.redhat.com/show_bug.cgi?id=860772
- https://fedorahosted.org/389/ticket/340
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.