First published: Fri Jul 26 2019(Updated: )
An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from another database during a SASL bind or with a proxyAuthz (RFC 4370) control. (It is not a common configuration to deploy a system where the server administrator and a DB administrator enjoy different levels of trust.)
Credit: CVE-2012-1164 CVE-2012-2668 CVE-2013-4449 CVE-2015-1545 CVE-2019-13057 CVE-2019-13565 cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/openldap | 2.4.57+dfsg-3+deb11u1 2.5.13+dfsg-5 2.5.18+dfsg-3 | |
macOS Catalina | <10.15.2 | 10.15.2 |
macOS Mojave | ||
macOS High Sierra | ||
OpenLDAP | <2.4.48 | |
Ubuntu | =12.04 | |
Ubuntu | =14.04 | |
Ubuntu | =16.04 | |
Ubuntu | =18.04 | |
Ubuntu | =19.04 | |
Debian | =8.0 | |
openSUSE | =15.0 | |
openSUSE | =15.1 | |
Apple iOS and macOS | >=10.13<10.13.6 | |
Apple iOS and macOS | >=10.14<10.14.6 | |
Apple iOS and macOS | >=10.15<10.15.2 | |
Apple iOS and macOS | =10.13.6 | |
Apple iOS and macOS | =10.13.6-security_update_2018-002 | |
Apple iOS and macOS | =10.13.6-security_update_2018-003 | |
Apple iOS and macOS | =10.13.6-security_update_2019-001 | |
Apple iOS and macOS | =10.13.6-security_update_2019-002 | |
Apple iOS and macOS | =10.13.6-security_update_2019-003 | |
Apple iOS and macOS | =10.13.6-security_update_2019-004 | |
Apple iOS and macOS | =10.13.6-security_update_2019-005 | |
Apple iOS and macOS | =10.13.6-security_update_2019-006 | |
Apple iOS and macOS | =10.14.6 | |
Apple iOS and macOS | =10.14.6 | |
Apple iOS and macOS | =10.14.6-security_update_2019-001 | |
McAfee Policy Auditor | <6.5.1 | |
McAfee Policy Auditor | =6.5.1 | |
oracle blockchain platform | <21.1.2 | |
Oracle Sun ZFS Storage Appliance Kit | =8.8 | |
Oracle Solaris SPARC | =11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2019-13057 is a vulnerability in OpenLDAP that was addressed in version 2.4.28.
macOS Catalina 10.15.2 is affected by CVE-2019-13057, but updating to version 2.4.28 of OpenLDAP resolves the issue.
Yes, macOS Mojave is affected by CVE-2019-13057, and updating OpenLDAP to version 2.4.28 is recommended.
Yes, macOS High Sierra is also affected by CVE-2019-13057, and updating OpenLDAP to version 2.4.28 is recommended.
You can find more information about CVE-2019-13057 at the following reference: [Apple Support](https://support.apple.com/en-us/HT210788)