CVE-2012-2678
published 2012-07-03CVE-2012-2678: 389 Directory Server before 1.2.11.6 (aka Red Hat Directory Server before 8.2.10-3), after the password for a LDAP user has been changed and before the server…
PriorityP418low1.2CVSS 2.0
AVLACHAuNCPINAN
EPSS
0.64%
46.5th percentile
389 Directory Server before 1.2.11.6 (aka Red Hat Directory Server before 8.2.10-3), after the password for a LDAP user has been changed and before the server has been reset, allows remote attackers to read the plaintext password via the unhashed#user#password attribute.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | 389-ds-base | — | — |
| fedoraproject | 389_directory_server | <= 1.2.11.5 | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| port389 | 389-ds-base | >= 0 < 1.3.2.16-0ubuntu1 | 1.3.2.16-0ubuntu1 |
| redhat | directory_server | <= 8.2 | — |
| redhat | directory_server | — | — |
CVSS provenance
nvdv2.01.2LOWAV:L/AC:H/Au:N/C:P/I:N/A:N
osv1.2LOW
vendor_debian1.2LOW
vendor_redhat1.2LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p843-jwrx-ghw2: 389 Directory Server before 1
ghsa_unreviewed·2022-05-17
CVE-2012-2678 [LOW] GHSA-p843-jwrx-ghw2: 389 Directory Server before 1
389 Directory Server before 1.2.11.6 (aka Red Hat Directory Server before 8.2.10-3), after the password for a LDAP user has been changed and before the server has been reset, allows remote attackers to read the plaintext password via the unhashed#user#password attribute.
OSV
CVE-2012-2678: 389 Directory Server before 1
osv·2012-07-03·CVSS 1.2
CVE-2012-2678 [LOW] CVE-2012-2678: 389 Directory Server before 1
389 Directory Server before 1.2.11.6 (aka Red Hat Directory Server before 8.2.10-3), after the password for a LDAP user has been changed and before the server has been reset, allows remote attackers to read the plaintext password via the unhashed#user#password attribute.
Red Hat
rhds/389: plaintext password disclosure flaw
vendor_redhat·2012-06-20·CVSS 1.2
CVE-2012-2678 [LOW] rhds/389: plaintext password disclosure flaw
rhds/389: plaintext password disclosure flaw
389 Directory Server before 1.2.11.6 (aka Red Hat Directory Server before 8.2.10-3), after the password for a LDAP user has been changed and before the server has been reset, allows remote attackers to read the plaintext password via the unhashed#user#password attribute.
Debian
CVE-2012-2678: 389-ds-base - 389 Directory Server before 1.2.11.6 (aka Red Hat Directory Server before 8.2.10...
vendor_debian·2012·CVSS 1.2
CVE-2012-2678 [LOW] CVE-2012-2678: 389-ds-base - 389 Directory Server before 1.2.11.6 (aka Red Hat Directory Server before 8.2.10...
389 Directory Server before 1.2.11.6 (aka Red Hat Directory Server before 8.2.10-3), after the password for a LDAP user has been changed and before the server has been reset, allows remote attackers to read the plaintext password via the unhashed#user#password attribute.
Scope: local
bookworm: resolved
bullseye: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-2678 CVE-2012-2746 389-ds-base various flaws [fedora-all]
bugzilla·2012-06-26·CVSS 1.2
CVE-2012-2678 [LOW] CVE-2012-2678 CVE-2012-2746 389-ds-base various flaws [fedora-all]
CVE-2012-2678 CVE-2012-2746 389-ds-base various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=829
Bugzilla
CVE-2012-2678 CVE-2012-2746 389-ds-base various flaws [epel-5]
bugzilla·2012-06-26·CVSS 1.2
CVE-2012-2678 [LOW] CVE-2012-2678 CVE-2012-2746 389-ds-base various flaws [epel-5]
CVE-2012-2678 CVE-2012-2746 389-ds-base various flaws [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=829933
Bugzilla
CVE-2012-2678 rhds/389: plaintext password disclosure flaw
bugzilla·2012-06-07·CVSS 1.2
CVE-2012-2678 [LOW] CVE-2012-2678 rhds/389: plaintext password disclosure flaw
CVE-2012-2678 rhds/389: plaintext password disclosure flaw
It was reported that, when a user changes their password in Red Hat Directory Server or 389, that the unhashed#user#password attribute (which stores the password in plaintext format, for the purposes of password policy and Windows sync), is available for any authenticed user to view. Any user who can successfully bind to the directory server can request and view this attribute under certain conditions, without administrative privileges. This attribute is only exposed in the time between a user changing their password and the directory server being restarted.
This was reported previously as a bug in 389, however the report only indicated that the exposure was to administrator logins, which is not the case.
https://fedorahosted.or
http://directory.fedoraproject.org/wiki/Release_Noteshttp://osvdb.org/83336http://rhn.redhat.com/errata/RHSA-2012-0997.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1041.htmlhttp://secunia.com/advisories/49734http://www.securityfocus.com/bid/54153https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03772083https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19353http://directory.fedoraproject.org/wiki/Release_Noteshttp://osvdb.org/83336http://rhn.redhat.com/errata/RHSA-2012-0997.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1041.htmlhttp://secunia.com/advisories/49734http://www.securityfocus.com/bid/54153https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03772083https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19353
2012-07-03
Published