CVE-2007-5794
published 2007-11-13CVE-2007-5794: Race condition in nss_ldap, when used in applications that are linked against the pthread library and fork after a call to nss_ldap, might send user data to…
PriorityP416medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
1.16%
63.8th percentile
Race condition in nss_ldap, when used in applications that are linked against the pthread library and fork after a call to nss_ldap, might send user data to the wrong process because of improper handling of the LDAP connection. NOTE: this issue was originally reported for Dovecot with the wrong mailboxes being returned, but other applications might also be affected.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libnss-ldap | < libnss-ldap 256-1 (bullseye) | libnss-ldap 256-1 (bullseye) |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8frr-8v9h-5c7m: Race condition in nss_ldap, when used in applications that are linked against the pthread library and fork after a call to nss_ldap, might send user d
ghsa_unreviewed·2022-05-01
CVE-2007-5794 [MEDIUM] CWE-362 GHSA-8frr-8v9h-5c7m: Race condition in nss_ldap, when used in applications that are linked against the pthread library and fork after a call to nss_ldap, might send user d
Race condition in nss_ldap, when used in applications that are linked against the pthread library and fork after a call to nss_ldap, might send user data to the wrong process because of improper handling of the LDAP connection. NOTE: this issue was originally reported for Dovecot with the wrong mailboxes being returned, but other applications might also be affected.
OSV
CVE-2007-5794: Race condition in nss_ldap, when used in applications that are linked against the pthread library and fork after a call to nss_ldap, might send user d
osv·2007-11-13·CVSS 4.3
CVE-2007-5794 [MEDIUM] CVE-2007-5794: Race condition in nss_ldap, when used in applications that are linked against the pthread library and fork after a call to nss_ldap, might send user d
Race condition in nss_ldap, when used in applications that are linked against the pthread library and fork after a call to nss_ldap, might send user data to the wrong process because of improper handling of the LDAP connection. NOTE: this issue was originally reported for Dovecot with the wrong mailboxes being returned, but other applications might also be affected.
Debian
CVE-2007-5794: libnss-ldap - Race condition in nss_ldap, when used in applications that are linked against th...
vendor_debian·2007·CVSS 4.3
CVE-2007-5794 [MEDIUM] CVE-2007-5794: libnss-ldap - Race condition in nss_ldap, when used in applications that are linked against th...
Race condition in nss_ldap, when used in applications that are linked against the pthread library and fork after a call to nss_ldap, might send user data to the wrong process because of improper handling of the LDAP connection. NOTE: this issue was originally reported for Dovecot with the wrong mailboxes being returned, but other applications might also be affected.
Scope: local
bullseye: resolved (fixed in 256-1)
Red Hat
nss_ldap randomly replying with wrong user's data
vendor_redhat·2005-04-09·CVSS 4.3
CVE-2007-5794 [MEDIUM] nss_ldap randomly replying with wrong user's data
nss_ldap randomly replying with wrong user's data
Race condition in nss_ldap, when used in applications that are linked against the pthread library and fork after a call to nss_ldap, might send user data to the wrong process because of improper handling of the LDAP connection. NOTE: this issue was originally reported for Dovecot with the wrong mailboxes being returned, but other applications might also be affected.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2007-5794 nss_ldap randomly replying with wrong user's data
bugzilla·2007-11-05·CVSS 4.3
CVE-2007-5794 [MEDIUM] CVE-2007-5794 nss_ldap randomly replying with wrong user's data
CVE-2007-5794 nss_ldap randomly replying with wrong user's data
+++ This bug was initially created as a clone of Bug #154314 +++
Description of problem:
Second time already when I hear nss_ldap is replying with wrong results and
causing peoples' mails to be shown to wrong people:
http://www.dovecot.org/list/dovecot/2005-March/006345.html
http://www.dovecot.org/list/dovecot/2005-April/006859.html
Something should really be done about this. At the very least I'm adding a check
to make sure getpwnam() returns the same user name that is being requested, and
if not put out some huge warnings about something being broken..
-- Additional comment from [email protected] on 2007-02-06 11:08 EST --
Oh yeah, got it.
The problem relies in the fact that if an application is linked against
pthre
Bugzilla
CVE-2007-5794 nss_ldap randomly replying with wrong user's data [rhel-4.7]
bugzilla·2005-04-17·CVSS 4.3
CVE-2007-5794 [MEDIUM] CVE-2007-5794 nss_ldap randomly replying with wrong user's data [rhel-4.7]
CVE-2007-5794 nss_ldap randomly replying with wrong user's data [rhel-4.7]
+++ This bug was initially created as a clone of Bug #154314 +++
From Bugzilla Helper:
User-Agent: Mozilla/5.0 (Macintosh; U; PPC Mac OS X Mach-O; en-US; rv:1.7.6)
Gecko/20050225 Firefox/1.0.1
Description of problem:
Second time already when I hear nss_ldap is replying with wrong results and
causing peoples' mails to be shown to wrong people:
http://www.dovecot.org/list/dovecot/2005-March/006345.html
http://www.dovecot.org/list/dovecot/2005-April/006859.html
Something should really be done about this. At the very least I'm adding a check
to make sure getpwnam() returns the same user name that is being requested, and
if not put out some huge warnings about something being broken..
Version-Release number of sele
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=453868http://bugs.gentoo.org/show_bug.cgi?id=198390http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00003.htmlhttp://secunia.com/advisories/27670http://secunia.com/advisories/27768http://secunia.com/advisories/27839http://secunia.com/advisories/28061http://secunia.com/advisories/28838http://secunia.com/advisories/29083http://secunia.com/advisories/30352http://secunia.com/advisories/31227http://secunia.com/advisories/31524http://security.gentoo.org/glsa/glsa-200711-33.xmlhttp://support.avaya.com/elmodocs2/security/ASA-2008-332.htmhttp://wiki.rpath.com/wiki/Advisories:rPSA-2007-0255http://www.debian.org/security/2007/dsa-1430http://www.dovecot.org/list/dovecot/2005-April/006859.htmlhttp://www.dovecot.org/list/dovecot/2005-March/006345.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:049http://www.redhat.com/support/errata/RHSA-2008-0389.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0715.htmlhttp://www.securityfocus.com/archive/1/487985/100/0/threadedhttp://www.securityfocus.com/bid/26452http://www.securitytracker.com/id?1020088https://bugzilla.redhat.com/show_bug.cgi?id=154314https://bugzilla.redhat.com/show_bug.cgi?id=367461https://exchange.xforce.ibmcloud.com/vulnerabilities/38505https://issues.rpath.com/browse/RPL-1913https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10625http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=453868http://bugs.gentoo.org/show_bug.cgi?id=198390http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00003.htmlhttp://secunia.com/advisories/27670http://secunia.com/advisories/27768http://secunia.com/advisories/27839http://secunia.com/advisories/28061http://secunia.com/advisories/28838http://secunia.com/advisories/29083http://secunia.com/advisories/30352http://secunia.com/advisories/31227http://secunia.com/advisories/31524http://security.gentoo.org/glsa/glsa-200711-33.xmlhttp://support.avaya.com/elmodocs2/security/ASA-2008-332.htmhttp://wiki.rpath.com/wiki/Advisories:rPSA-2007-0255http://www.debian.org/security/2007/dsa-1430http://www.dovecot.org/list/dovecot/2005-April/006859.htmlhttp://www.dovecot.org/list/dovecot/2005-March/006345.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:049http://www.redhat.com/support/errata/RHSA-2008-0389.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0715.htmlhttp://www.securityfocus.com/archive/1/487985/100/0/threadedhttp://www.securityfocus.com/bid/26452http://www.securitytracker.com/id?1020088https://bugzilla.redhat.com/show_bug.cgi?id=154314https://bugzilla.redhat.com/show_bug.cgi?id=367461https://exchange.xforce.ibmcloud.com/vulnerabilities/38505https://issues.rpath.com/browse/RPL-1913https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10625
2007-11-13
Published