CVE-2012-2746: Low severity redhat Directory Server vulnerability
389 Directory Server before 1.2.11.6 (aka Red Hat Directory Server before 8.2.10-3), when the password of a LDAP user has been changed and audit logging is enabled, saves the new password to the log in plain text, which allows remote authenticated users to read the password.
Other sources
A flaw was found [1] in the way 389 Directory Server and Red Hat Directory Server handled logging to the audit log. When a user changed their password in the directory, the new password would be written to the audit log in plaintext.
Although the directory server administrator can configure the path and permissions of the audit log, by default it is mode 0600, owned by the directory server user, and is located in the directory server log directory (/var/log/dirsrv/slapd-[hostname]), which is mode 0770 and owned by the directory server user ("nobody", by default)
[1] https://fedorahosted.org/389/ticket/365
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2746?
CVE-2012-2746 has a moderate severity level due to the risk of sensitive password information exposure.
How do I fix CVE-2012-2746?
To fix CVE-2012-2746, upgrade your version of 389 Directory Server to 1.2.11.6 or later.
What types of users are affected by CVE-2012-2746?
This vulnerability affects remote authenticated users who can access the audit logs.
What versions of 389 Directory Server are vulnerable to CVE-2012-2746?
CVE-2012-2746 affects versions prior to 1.2.11.6 of 389 Directory Server.
Can I mitigate CVE-2012-2746 without upgrading?
Mitigation without upgrading is not recommended as it involves complex configurations that may not completely eliminate the risk.