VulnerabilityModified
CVE-2014-0132
The SASL authentication functionality in 389 Directory Server before 1.2.11.26 allows remote authenticated users to connect as an arbitrary user and gain privileges via the authzid parameter in a SASL/GSSAPI bind.
MEDIUM 6.5EPSS 2.19%
Does this matter?
Lower severity and a low EPSS score (2.19%). Track it; it rarely justifies an emergency change on its own.
Description
The SASL authentication functionality in 389 Directory Server before 1.2.11.26 allows remote authenticated users to connect as an arbitrary user and gain privileges via the authzid parameter in a SASL/GSSAPI bind.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 2.19% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- fedoraproject/389 directory server
- Source
- secalert@redhat.com
References
- http://rhn.redhat.com/errata/RHSA-2014-0292.html
- http://secunia.com/advisories/57412Vendor Advisory
- http://secunia.com/advisories/57427Vendor Advisory
- https://fedorahosted.org/389/changeset/76acff12a86110d4165f94e2cba13ef5c7ebc38a/Exploit
- https://fedorahosted.org/389/ticket/47739Patch
- http://rhn.redhat.com/errata/RHSA-2014-0292.html
- http://secunia.com/advisories/57412Vendor Advisory
- http://secunia.com/advisories/57427Vendor Advisory
- https://fedorahosted.org/389/changeset/76acff12a86110d4165f94e2cba13ef5c7ebc38a/Exploit
- https://fedorahosted.org/389/ticket/47739Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.