CVE-2013-1897
Published May 13, 2013
Last updated 12 years ago
Overview
- Description
- The do_search function in ldap/servers/slapd/search.c in 389 Directory Server 1.2.x before 1.2.11.20 and 1.3.x before 1.3.0.5 does not properly restrict access to entries when the nsslapd-allow-anonymous-access configuration is set to rootdse and the BASE search scope is used, which allows remote attackers to obtain sensitive information outside of the rootDSE via a crafted LDAP search.
- Source
- secalert@redhat.com
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 2.6
- Impact score
- 2.9
- Exploitability score
- 4.9
- Vector string
- AV:N/AC:H/Au:N/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-264
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CE2E9C8D-FFEE-424C-BBA6-42BD4309D18A" }, { "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8F2E9CEF-F30D-4374-A7E2-052102B602A7" }, { "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "16A8729B-B00B-4871-B083-6B10A5034721" }, { "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6335FA65-9498-40AF-AE2B-034DA2823821" }, { "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.5:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8CF92ADB-B5B0-43D7-93D8-CBA3AE46EB8D" }, { "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.5:rc2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "17F8ED59-E27A-4B9B-8BB8-66FAB2B2DCFB" }, { "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.5:rc3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4200CEAB-4E14-48C8-9D6F-F86796475019" }, { "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.5:rc4:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3179916B-F98C-4D10-82AB-59DCCACBE8DA" }, { "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B44B5289-08BB-4D62-B60D-1BD738472B1D" }, { "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.6:a2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "02392BBF-AFAB-4739-BAF6-E930692AB28F" }, { "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.6:a3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BFF70436-E01E-4912-AC31-B600F5E8CB4F" }, { "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.6:a4:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "360BA51B-B47E-4537-B564-9E628DF4E6EA" }, { "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.6:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "987F04BC-75DC-4959-AE32-070F11F9EBC2" }, { "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.6:rc2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "078BCE55-90BB-48DE-92D1-9A152338158C" }, { "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.6:rc3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "595F5AEE-E4A9-40E0-AF03-69AF689C4916" }, { "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.6:rc6:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FED47519-F254-4545-8551-FFBD0B4F9FAB" }, { "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.6:rc7:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A06C0421-74B7-4F9D-9F3A-18BF62BDD4D9" }, { "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.6.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "83F772DF-B8A7-4577-9AC6-3234B8C7FFAA" }, { "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.7:alpha3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "60624BFB-BB50-47F9-BB6D-BC92B40988BF" }, { "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.7.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "17C879AE-7435-43F5-94E5-A7ED84E46D0F" }, { "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.8:alpha1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5809DC7B-AC50-4E03-A8FA-6C2C6B67A400" }, { "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.8:alpha2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "04FED7B7-7D97-4020-9D5C-A7150B43838C" }, { "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.8:alpha3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6CA6BAB0-4638-4341-8835-E24E58855C37" }, { "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.8:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3C87A154-D750-4A93-B958-478CB17783F1" }, { "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.8:rc2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "762AF16D-D7C3-4444-B8E5-88626D7DCE6A" }, { "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.8.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2FF2BE2A-E90A-4336-864A-A76D9B1F0793" }, { "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.8.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7EE57DD6-A59C-4073-8DBB-E8D667E9A206" }, { "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.8.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5F65E0F9-731B-48E4-AF46-C8CAAE00820D" }, { "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.9.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B8AD8024-EF26-46B3-80E1-25661A5C538A" }, { "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.10:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2B8B6754-F47D-4E51-BB5E-020B6546D906" }, { "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.10:alpha8:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A3DD52CC-C56A-4F62-BE61-BF826104B127" }, { "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.10:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D820510A-C85F-4F5D-895E-884DB70A409F" }, { "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.10.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5D661F57-BECB-4880-A14F-F9DB3C6659C2" }, { "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.10.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1B6E8AC0-9017-4C68-BEA8-AC89642C74A3" }, { "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.10.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9BFCE99E-C862-4A32-BFB1-799F835045AE" }, { "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.10.11:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D1DE676D-9EB2-4FBB-B9D8-AFF71345F92D" }, { "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.11.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CCBE4443-C736-4263-BC89-5A8F2ADD81E7" }, { "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.11.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8D64150B-1D48-4966-873C-029747495BB3" }, { "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.11.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "80F7CCAD-04B1-4BE1-BE61-791C5CA3984E" }, { "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.11.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "11943F1C-BD6D-4339-A381-5E4A33120383" }, { "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.11.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1BAA555B-4F2B-408D-9A4C-1740AFC228DC" }, { "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.11.10:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "60E619C3-7E6D-4235-ACE5-67524CD38AA1" }, { "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.11.11:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8ED48D0E-1C9A-4FB8-B54E-F1B121D68045" }, { "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.11.12:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9A7DFDE6-7C1F-4AB2-8719-50B44D25620F" }, { "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.11.13:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F102D5BD-8B5F-47BF-A94C-923F0BEE943E" }, { "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.11.14:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "912A37B4-1E3B-40AB-8B63-720F84365843" }, { "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.11.15:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "16C83007-E3C8-40D0-ADAE-E7EE87CCA464" }, { "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.11.17:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "608BF64E-4204-4610-B23C-BC206E870F79" }, { "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.11.19:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "10315DCC-28D6-400C-92C1-C0AD5E3DDF53" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.3.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7C7B3AF4-72F4-4242-84A5-1C5096BB42B2" }, { "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.3.0.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "22BA10F4-510E-4D25-9DA6-BC475EEA5F12" }, { "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.3.0.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3766F68E-448D-4298-B0CE-1A37497984DD" } ], "operator": "OR" } ] } ]