CVE-2012-0833
03.07.2012, 16:40
The acllas__handle_group_entry function in servers/plugins/acl/acllas.c in 389 Directory Server before 1.2.10 does not properly handled access control instructions (ACIs) that use certificate groups, which allows remote authenticated LDAP users with a certificate group to cause a denial of service (infinite loop and CPU consumption) by binding to the server.Enginsight
Vendor | Product | Version |
---|---|---|
fedoraproject | 389_directory_server | 𝑥 ≤ 1.2.10 |
fedoraproject | 389_directory_server | 1.2.1 |
fedoraproject | 389_directory_server | 1.2.2 |
fedoraproject | 389_directory_server | 1.2.3 |
fedoraproject | 389_directory_server | 1.2.5 |
fedoraproject | 389_directory_server | 1.2.5:rc1 |
fedoraproject | 389_directory_server | 1.2.5:rc2 |
fedoraproject | 389_directory_server | 1.2.5:rc3 |
fedoraproject | 389_directory_server | 1.2.5:rc4 |
fedoraproject | 389_directory_server | 1.2.6 |
fedoraproject | 389_directory_server | 1.2.6:a2 |
fedoraproject | 389_directory_server | 1.2.6:a3 |
fedoraproject | 389_directory_server | 1.2.6:a4 |
fedoraproject | 389_directory_server | 1.2.6:rc1 |
fedoraproject | 389_directory_server | 1.2.6:rc2 |
fedoraproject | 389_directory_server | 1.2.6:rc3 |
fedoraproject | 389_directory_server | 1.2.6:rc6 |
fedoraproject | 389_directory_server | 1.2.6:rc7 |
fedoraproject | 389_directory_server | 1.2.6.1 |
fedoraproject | 389_directory_server | 1.2.7:alpha3 |
fedoraproject | 389_directory_server | 1.2.7.5 |
fedoraproject | 389_directory_server | 1.2.8:alpha1 |
fedoraproject | 389_directory_server | 1.2.8:alpha2 |
fedoraproject | 389_directory_server | 1.2.8:alpha3 |
fedoraproject | 389_directory_server | 1.2.8:rc1 |
fedoraproject | 389_directory_server | 1.2.8:rc2 |
fedoraproject | 389_directory_server | 1.2.8.1 |
fedoraproject | 389_directory_server | 1.2.8.2 |
fedoraproject | 389_directory_server | 1.2.8.3 |
fedoraproject | 389_directory_server | 1.2.9.9 |
fedoraproject | 389_directory_server | 1.2.10:alpha8 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References