MGASA-2015-0183
Dashboard / Vulnerabilities / MGASA-2015-0183
Summary: Updated 389-ds-base packages fix CVE-2015-1854
Details: Updated 389-ds-base packages fix security vulnerability: A flaw was found in the way Red Hat Directory Server performed authorization of modrdn operations. An unauthenticated attacker able to issue an ldapmodrdn call to the directory server could use this flaw to perform unauthorized modifications of entries in the directory server (CVE-2015-1854).
References: https://advisories.mageia.org/MGASA-2015-0183.html, https://bugs.mageia.org/show_bug.cgi?id=15796, https://rhn.redhat.com/errata/RHSA-2015-0895.html
Affected packages
Package
Name: 389-ds-base
Purl: pkg:rpm/mageia/389-ds-base?arch=source&distro=mageia-4
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -1.3.3.10-1.mga4
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
