MGASA-2013-0357
Dashboard / Vulnerabilities / MGASA-2013-0357
Summary: Updated 389-ds-base package fixes CVE-2013-4485
Details: Updated 389-ds-base packages fix security vulnerability: It was discovered that the 389 Directory Server did not properly handle certain Get Effective Rights (GER) search queries when the attribute list, which is a part of the query, included several names using the '@' character. An attacker able to submit search queries to the 389 Directory Server could cause it to crash (CVE-2013-4485).
References: https://advisories.mageia.org/MGASA-2013-0357.html, http://port389.org/wiki/Releases/1.3.0.9, https://rhn.redhat.com/errata/RHSA-2013-1752.html, https://bugs.mageia.org/show_bug.cgi?id=11720
Affected packages
Package
Name: 389-ds-base
Purl: pkg:rpm/mageia/389-ds-base?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
