CVE-2013-1897
389 Directory Server 1.2.x < 1.2.11.20 and 1.3.x < 1.3.0.5 - Information Disclosure via BASE Search
Title source: llmDescription
The do_search function in ldap/servers/slapd/search.c in 389 Directory Server 1.2.x before 1.2.11.20 and 1.3.x before 1.3.0.5 does not properly restrict access to entries when the nsslapd-allow-anonymous-access configuration is set to rootdse and the BASE search scope is used, which allows remote attackers to obtain sensitive information outside of the rootDSE via a crafted LDAP search.
References (6)
Core 6
Core References
Vendor Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-0742.html
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101323.html
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=928105
Vendor Advisory x_refsource_confirm
https://fedorahosted.org/freeipa/ticket/3540
Various Sources x_refsource_confirm
https://fedorahosted.org/389/ticket/47308
Scores
EPSS
0.0210
EPSS Percentile
79.7%
Details
CWE
CWE-264
Status
published
Products (32)
fedoraproject/389_directory_server
1.2.1
fedoraproject/389_directory_server
1.2.2
fedoraproject/389_directory_server
1.2.3
fedoraproject/389_directory_server
1.2.5 (5 CPE variants)
fedoraproject/389_directory_server
1.2.6 (9 CPE variants)
fedoraproject/389_directory_server
1.2.6.1
fedoraproject/389_directory_server
1.2.7 alpha3
fedoraproject/389_directory_server
1.2.7.5
fedoraproject/389_directory_server
1.2.8 alpha1 (5 CPE variants)
fedoraproject/389_directory_server
1.2.8.1
... and 22 more
Published
May 13, 2013
Tracked Since
Feb 18, 2026