First published: Tue Mar 10 2015(Updated: )
389 Directory Server before 1.3.2.27 and 1.3.3.x before 1.3.3.9 does not properly restrict access to the "cn=changelog" LDAP sub-tree, which allows remote attackers to obtain sensitive information from the changelog via unspecified vectors.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fedoraproject 389 Directory Server | <=1.3.2.26 | |
Fedoraproject 389 Directory Server | =1.3.3.0 | |
Fedoraproject 389 Directory Server | =1.3.3.2 | |
Fedoraproject 389 Directory Server | =1.3.3.3 | |
Fedoraproject 389 Directory Server | =1.3.3.5 | |
Fedoraproject 389 Directory Server | =1.3.3.8 | |
Fedoraproject Fedora | =22 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.