CVE-2012-4450
published 2012-10-01CVE-2012-4450: 389 Directory Server 1.2.10 does not properly update the ACL when a DN entry is moved by a modrdn operation, which allows remote authenticated users with…
PriorityP432medium6CVSS 2.0
AVNACMAuSCPIPAP
EPSS
1.86%
76.9th percentile
389 Directory Server 1.2.10 does not properly update the ACL when a DN entry is moved by a modrdn operation, which allows remote authenticated users with certain permissions to bypass ACL restrictions and access the DN entry.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | 389-ds-base | < 389-ds-base 1.2.11.15-1 (bookworm) | 389-ds-base 1.2.11.15-1 (bookworm) |
| fedoraproject | 389_directory_server | — | — |
| port389 | 389-ds-base | >= 0 < 1.2.11.15-1 | 1.2.11.15-1 |
| port389 | 389-ds-base | >= 0 < 1.2.11.15-1 | 1.2.11.15-1 |
| port389 | 389-ds-base | >= 0 < 1.2.11.15-1 | 1.2.11.15-1 |
CVSS provenance
nvdv2.06.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
osv6.0MEDIUM
vendor_debian6.0MEDIUM
vendor_redhat6.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hxpc-5pf5-9xxg: 389 Directory Server 1
ghsa_unreviewed·2022-05-17
CVE-2012-4450 [MEDIUM] GHSA-hxpc-5pf5-9xxg: 389 Directory Server 1
389 Directory Server 1.2.10 does not properly update the ACL when a DN entry is moved by a modrdn operation, which allows remote authenticated users with certain permissions to bypass ACL restrictions and access the DN entry.
OSV
CVE-2012-4450: 389 Directory Server 1
osv·2012-10-01·CVSS 6.0
CVE-2012-4450 [MEDIUM] CVE-2012-4450: 389 Directory Server 1
389 Directory Server 1.2.10 does not properly update the ACL when a DN entry is moved by a modrdn operation, which allows remote authenticated users with certain permissions to bypass ACL restrictions and access the DN entry.
Red Hat
389-ds-base: Change on SLAPI_MODRDN_NEWSUPERIOR is not evaluated in ACL (ACL rules bypass possible)
vendor_redhat·2012-04-16·CVSS 6.0
CVE-2012-4450 [MEDIUM] 389-ds-base: Change on SLAPI_MODRDN_NEWSUPERIOR is not evaluated in ACL (ACL rules bypass possible)
389-ds-base: Change on SLAPI_MODRDN_NEWSUPERIOR is not evaluated in ACL (ACL rules bypass possible)
389 Directory Server 1.2.10 does not properly update the ACL when a DN entry is moved by a modrdn operation, which allows remote authenticated users with certain permissions to bypass ACL restrictions and access the DN entry.
Debian
CVE-2012-4450: 389-ds-base - 389 Directory Server 1.2.10 does not properly update the ACL when a DN entry is ...
vendor_debian·2012·CVSS 6.0
CVE-2012-4450 [MEDIUM] CVE-2012-4450: 389-ds-base - 389 Directory Server 1.2.10 does not properly update the ACL when a DN entry is ...
389 Directory Server 1.2.10 does not properly update the ACL when a DN entry is moved by a modrdn operation, which allows remote authenticated users with certain permissions to bypass ACL restrictions and access the DN entry.
Scope: local
bookworm: resolved (fixed in 1.2.11.15-1)
bullseye: resolved (fixed in 1.2.11.15-1)
sid: resolved (fixed in 1.2.11.15-1)
trixie: resolved (fixed in 1.2.11.15-1)
No detection rules found.
Bugzilla
CVE-2012-4450 389-ds-base: Change on SLAPI_MODRDN_NEWSUPERIOR is not evaluated in ACL (ACL rules bypass possible)
bugzilla·2012-09-26·CVSS 6.0
CVE-2012-4450 [MEDIUM] CVE-2012-4450 389-ds-base: Change on SLAPI_MODRDN_NEWSUPERIOR is not evaluated in ACL (ACL rules bypass possible)
CVE-2012-4450 389-ds-base: Change on SLAPI_MODRDN_NEWSUPERIOR is not evaluated in ACL (ACL rules bypass possible)
A possibility to bypass access control list (ACL) definitions was found in the way 389 Directory Server performed LDAP modifyRDN operation upon request from client. When a user has been granted access to set of DN entries, but denied access to a specific subset of those entries, it was possible the user to obtain temporary (till next Directory Server restart) access to that subset of entries (they should not have had otherwise ability to access) when the DN entry was moved via database modify RDN function.
Upstream ticket:
[1] https://fedorahosted.org/389/ticket/340
Relevant upstream patch:
[2] http://git.fedorahosted.org/cgit/389/ds.git/commit/?id=5beb93d42efb807838c09c5fab
Bugzilla
CVE-2012-4450 389-ds-base: Change on SLAPI_MODRDN_NEWSUPERIOR is not evaluated in ACL (ACL rules bypass possible) [epel-5]
bugzilla·2012-09-26·CVSS 6.0
CVE-2012-4450 [MEDIUM] CVE-2012-4450 389-ds-base: Change on SLAPI_MODRDN_NEWSUPERIOR is not evaluated in ACL (ACL rules bypass possible) [epel-5]
CVE-2012-4450 389-ds-base: Change on SLAPI_MODRDN_NEWSUPERIOR is not evaluated in ACL (ACL rules bypass possible) [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admi
Bugzilla
CVE-2012-4450 389-ds-base: Change on SLAPI_MODRDN_NEWSUPERIOR is not evaluated in ACL (ACL rules bypass possible) [fedora-all]
bugzilla·2012-09-26·CVSS 6.0
CVE-2012-4450 [MEDIUM] CVE-2012-4450 389-ds-base: Change on SLAPI_MODRDN_NEWSUPERIOR is not evaluated in ACL (ACL rules bypass possible) [fedora-all]
CVE-2012-4450 389-ds-base: Change on SLAPI_MODRDN_NEWSUPERIOR is not evaluated in ACL (ACL rules bypass possible) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://
http://git.fedorahosted.org/cgit/389/ds.git/commit/?id=5beb93d42efb807838c09c5fab898876876f8d09http://rhn.redhat.com/errata/RHSA-2013-0503.htmlhttp://secunia.com/advisories/50713http://www.openwall.com/lists/oss-security/2012/09/26/3http://www.openwall.com/lists/oss-security/2012/09/26/5http://www.securityfocus.com/bid/55690https://bugzilla.redhat.com/show_bug.cgi?id=860772https://fedorahosted.org/389/ticket/340http://git.fedorahosted.org/cgit/389/ds.git/commit/?id=5beb93d42efb807838c09c5fab898876876f8d09http://rhn.redhat.com/errata/RHSA-2013-0503.htmlhttp://secunia.com/advisories/50713http://www.openwall.com/lists/oss-security/2012/09/26/3http://www.openwall.com/lists/oss-security/2012/09/26/5http://www.securityfocus.com/bid/55690https://bugzilla.redhat.com/show_bug.cgi?id=860772https://fedorahosted.org/389/ticket/340
2012-10-01
Published