MGASA-2015-0108

    Dashboard / Vulnerabilities / MGASA-2015-0108

    MGASA-2015-0108

    Published: 14 Mar 2015Last Modified: 16 Apr 2026

    Summary: Updated 389-ds-base packages fix security vulnerabilities

    Details: An information disclosure flaw was found in the way the 389 Directory Server stored information in the Changelog that is exposed via the 'cn=changelog' LDAP sub-tree. An unauthenticated user could in certain cases use this flaw to read data from the Changelog, which could include sensitive information such as plain-text passwords (CVE-2014-8105). It was found that when the nsslapd-unhashed-pw-switch 389 Directory Server configuration option was set to "off", it did not prevent the writing of unhashed passwords into the Changelog. This could potentially allow an authenticated user able to access the Changelog to read sensitive information (CVE-2014-8112).

    Affected packages

    Package

    Name: 389-ds-base

    Purl: pkg:rpm/mageia/389-ds-base?arch=source&distro=mageia-4

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.3.3.9-1.mga4

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High