CVE-2014-8105
10.03.2015, 14:59
389 Directory Server before 1.3.2.27 and 1.3.3.x before 1.3.3.9 does not properly restrict access to the "cn=changelog" LDAP sub-tree, which allows remote attackers to obtain sensitive information from the changelog via unspecified vectors.Enginsight
| Vendor | Product | Version |
|---|---|---|
| fedoraproject | 389_directory_server | 𝑥 ≤ 1.3.2.26 |
| fedoraproject | 389_directory_server | 1.3.3.0 |
| fedoraproject | 389_directory_server | 1.3.3.2 |
| fedoraproject | 389_directory_server | 1.3.3.3 |
| fedoraproject | 389_directory_server | 1.3.3.5 |
| fedoraproject | 389_directory_server | 1.3.3.8 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 389-ds-base |
| ||||||||||||||||||||||||||
| freeipa |
|
Common Weakness Enumeration
References