MGASA-2017-0340
Dashboard / Vulnerabilities / MGASA-2017-0340
Summary: Updated 389-ds-base packages fix security vulnerability
Details: The directory server password lockout policy prevents binds from operating once a threshold of failed passwords has been met. During this lockout, if you bind with a successful password, a different error code is returned. This means that an attacker has no ratelimit or penalty during an account lock, and can continue to attempt passwords via bruteforce, using the change in return code to ascertain a sucessful password auth (CVE-2017-7551).
References: https://advisories.mageia.org/MGASA-2017-0340.html, https://bugs.mageia.org/show_bug.cgi?id=21671, https://access.redhat.com/errata/RHSA-2017:2569
Affected packages
Package
Name: 389-ds-base
Purl: pkg:rpm/mageia/389-ds-base?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
