Red Hat Security Advisory 2016-2765-01

Discussion in 'News Aggregator' started by Packet Storm, 16 Nov 2016.

  1. Packet Storm

    Packet Storm Guest

    Red Hat Security Advisory 2016-2765-01 - 389 Directory Server is an LDAP version 3 compliant server. The base packages include the Lightweight Directory Access Protocol server and command-line utilities for server administration. Security Fix: It was found that 389 Directory Server was vulnerable to a flaw in which the default ACI could be read by an anonymous user. This could lead to leakage of sensitive information. An information disclosure flaw was found in 389 Directory Server. A user with no access to objects in certain LDAP sub-tree could send LDAP ADD operations with a specific object name. The error message returned to the user was different based on whether the target object existed or not.

    Continue reading...
     

Share This Page

Loading...