First published: Fri Jun 28 2013(Updated: )
A flaw was found in how Red Hat Directory Server and the 389 Directory Server would handle access controls to certain attributes of an entry. A user with access to the Directory Server could use a series of searches to guess the values of other attributes that they should not be able to see. If a user had access (authenticated or anonymous, depending on whether or not the Directory Server allows anonymous access), they could use this to obtain information that should be restricted due to access controls.
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Directory Server | ||
Red Hat Directory Server |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-979508 is classified as moderate due to potential unauthorized access to sensitive attribute values.
To fix REDHAT-BUG-979508, it is recommended to apply the latest security patches provided by Red Hat for the affected directory servers.
Users and administrators of Red Hat Directory Server and Red Hat 389 Directory Server are affected by REDHAT-BUG-979508.
The flaw in REDHAT-BUG-979508 involves improper access control that allows users to infer other attribute values through crafted searches.
A workaround for REDHAT-BUG-979508 includes tightening access controls and monitoring directory access to minimize potential exploits.