CVE-2014-0132: Medium severity Fedoraproject 389 Directory Server vulnerability
Published Mar 18, 2014
·Updated
The SASL authentication functionality in 389 Directory Server before 1.2.11.26 allows remote authenticated users to connect as an arbitrary user and gain privileges via the authzid parameter in a SASL/GSSAPI bind.
Affected Software
18 affected components
Fedoraproject 389 Directory Server<=1.2.11.25
Fedoraproject 389 Directory Server=1.2.11.1
Fedoraproject 389 Directory Server=1.2.11.5
Fedoraproject 389 Directory Server=1.2.11.6
Fedoraproject 389 Directory Server=1.2.11.8
Fedoraproject 389 Directory Server=1.2.11.9
Fedoraproject 389 Directory Server=1.2.11.10
Fedoraproject 389 Directory Server=1.2.11.11
Fedoraproject 389 Directory Server=1.2.11.12
Fedoraproject 389 Directory Server=1.2.11.13
Fedoraproject 389 Directory Server=1.2.11.14
Fedoraproject 389 Directory Server=1.2.11.15
Fedoraproject 389 Directory Server=1.2.11.17
Fedoraproject 389 Directory Server=1.2.11.19
Fedoraproject 389 Directory Server=1.2.11.20
Fedoraproject 389 Directory Server=1.2.11.21
Fedoraproject 389 Directory Server=1.2.11.22
Fedoraproject 389 Directory Server=1.2.11.23
Remediation
Patch Available
Event History
Mar 18, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·05:02 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-0132?
CVE-2014-0132 is classified as a medium severity vulnerability.
2
How do I fix CVE-2014-0132?
To fix CVE-2014-0132, upgrade to 389 Directory Server version 1.2.11.26 or later.
3
What are the affected versions for CVE-2014-0132?
CVE-2014-0132 affects 389 Directory Server versions prior to 1.2.11.26.
4
Can CVE-2014-0132 be exploited remotely?
Yes, CVE-2014-0132 can be exploited by remote authenticated users to gain higher privileges.
5
What is the main impact of CVE-2014-0132?
The main impact of CVE-2014-0132 is that it allows unauthorized access to arbitrary user privileges.