REDHAT-BUG-1525628: Medium severity red hat directory server vulnerability
A flaw was found in 389-ds-base that was introduced after CVE-2016-5405 fix. A lack of size check in slapictmemcmp() function may lead to authentication bypass through pre-hashed userPassword attributes under highly specific circumstances.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1525628?
REDHAT-BUG-1525628 has been classified with a moderate severity level due to the potential authentication bypass.
How do I fix REDHAT-BUG-1525628?
To mitigate REDHAT-BUG-1525628, upgrade to the latest version of Red Hat 389-ds-base that addresses this vulnerability.
What versions are affected by REDHAT-BUG-1525628?
REDHAT-BUG-1525628 affects Red Hat 389-ds-base versions prior to 1.3.0.
Is an authentication bypass possible with REDHAT-BUG-1525628?
Yes, REDHAT-BUG-1525628 allows for possible authentication bypass through pre-hashed userPassword attributes under specific conditions.
What function is implicated in REDHAT-BUG-1525628?
The vulnerability identified in REDHAT-BUG-1525628 is attributed to a flaw in the slapi_ct_memcmp() function.