CVE-2012-4450: Medium severity Fedoraproject 389 Directory Server vulnerability
Published Oct 1, 2012
·Updated
389 Directory Server 1.2.10 does not properly update the ACL when a DN entry is moved by a modrdn operation, which allows remote authenticated users with certain permissions to bypass ACL restrictions and access the DN entry.
Affected Software
1 affected component
Fedoraproject 389 Directory Server=1.2.10
Remediation
Event History
Oct 1, 2012
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-4450?
CVE-2012-4450 is classified as a medium severity vulnerability.
2
How do I fix CVE-2012-4450?
To remediate CVE-2012-4450, upgrade to a version of 389 Directory Server that has addressed this issue.
3
Who is affected by CVE-2012-4450?
Remote authenticated users with certain permissions on systems running 389 Directory Server 1.2.10 are affected by CVE-2012-4450.
4
What is the impact of CVE-2012-4450?
CVE-2012-4450 allows unauthorized access to DN entries by bypassing Access Control Lists.
5
What versions are vulnerable to CVE-2012-4450?
The specific vulnerable version is 389 Directory Server 1.2.10.