First published: Thu Jul 03 2008(Updated: )
A flaw was found in a Accept Language HTTP header parsers implemented in adminutil library used by various Red Hat Directory Server's Administration Server's CGI scripts. A remote attacker able to connect to Administration Server web interface could cause a CGI scripts to crash, or possibly execute an arbitrary code. Issue affects: - Red Hat Directory Server 7.1 - adminutil packages shipped in Red Hat Directory Server 8 and Fedora Directory Server, prior to adminutil version 1.1.7
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Directory Server | =7.1 | |
Red Hat Adminutil | <1.1.7 | |
Red Hat 389 Directory Server | <1.1.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-453916 is classified as a moderate security vulnerability.
To fix REDHAT-BUG-453916, update your Red Hat Directory Server and adminutil to the latest patched versions.
REDHAT-BUG-453916 affects Red Hat Directory Server 7.1 and Red Hat adminutil versions up to 1.1.7.
Yes, a remote attacker with access to the Administration Server web interface can exploit REDHAT-BUG-453916.
Using REDHAT-BUG-453916, an attacker could potentially cause CGI scripts to crash or execute arbitrary code.