CVE-2017-15135: High severity red hat 389 directory server vulnerability
A flaw was found in 389-ds-base that was introduced after CVE-2016-5405 fix. A lack of size check in slapictmemcmp() function may lead to authentication bypass through pre-hashed userPassword attributes under highly specific circumstances.
Other sources
It was found that 389-ds-base since 1.3.6.1 up to and including 1.4.0.3 did not always handle internal hash comparison operations correctly during the authentication process. A remote, unauthenticated attacker could potentially use this flaw to bypass the authentication process under very rare and specific circumstances.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2017-15135?
CVE-2017-15135 is a vulnerability found in 389-ds-base version 1.3.6.1 up to and including 1.4.0.3 that allows a remote attacker to bypass the authentication process.
How does CVE-2017-15135 affect 389-ds-base?
CVE-2017-15135 affects 389-ds-base version 1.3.6.1 up to and including 1.4.0.3.
What is the severity of CVE-2017-15135?
The severity of CVE-2017-15135 is high with a CVSS score of 8.1.
How can an attacker exploit CVE-2017-15135?
An attacker can exploit CVE-2017-15135 by using the vulnerability to bypass the authentication process.
Is there a fix available for CVE-2017-15135?
Yes, a fix is available for CVE-2017-15135. It is recommended to update to 389-ds-base version 1.4.0.4 or later.