CVE-2014-3562
published 2014-08-21CVE-2014-3562: Red Hat Directory Server 8 and 389 Directory Server, when debugging is enabled, allows remote attackers to obtain sensitive replicated metadata by searching…
PriorityP424medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
2.20%
80.5th percentile
Red Hat Directory Server 8 and 389 Directory Server, when debugging is enabled, allows remote attackers to obtain sensitive replicated metadata by searching the directory.
Affected
51 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | 389-ds-base | < 389-ds-base 1.3.2.21-1 (bookworm) | 389-ds-base 1.3.2.21-1 (bookworm) |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6vvf-j83f-44mh: Red Hat Directory Server 8 and 389 Directory Server, when debugging is enabled, allows remote attackers to obtain sensitive replicated metadata by sea
ghsa_unreviewed·2022-05-14
CVE-2014-3562 [MEDIUM] CWE-200 GHSA-6vvf-j83f-44mh: Red Hat Directory Server 8 and 389 Directory Server, when debugging is enabled, allows remote attackers to obtain sensitive replicated metadata by sea
Red Hat Directory Server 8 and 389 Directory Server, when debugging is enabled, allows remote attackers to obtain sensitive replicated metadata by searching the directory.
OSV
CVE-2014-3562: Red Hat Directory Server 8 and 389 Directory Server, when debugging is enabled, allows remote attackers to obtain sensitive replicated metadata by sea
osv·2014-08-21·CVSS 5.0
CVE-2014-3562 [MEDIUM] CVE-2014-3562: Red Hat Directory Server 8 and 389 Directory Server, when debugging is enabled, allows remote attackers to obtain sensitive replicated metadata by sea
Red Hat Directory Server 8 and 389 Directory Server, when debugging is enabled, allows remote attackers to obtain sensitive replicated metadata by searching the directory.
Red Hat
389-ds: unauthenticated information disclosure
vendor_redhat·2014-08-07·CVSS 5.0
CVE-2014-3562 [MEDIUM] CWE-862 389-ds: unauthenticated information disclosure
389-ds: unauthenticated information disclosure
Red Hat Directory Server 8 and 389 Directory Server, when debugging is enabled, allows remote attackers to obtain sensitive replicated metadata by searching the directory.
It was found that when replication was enabled for each attribute in Red Hat Directory Server / 389 Directory Server, which is the default configuration, the server returned replicated metadata when the directory was searched while debugging was enabled. A remote attacker could use this flaw to disclose potentially sensitive information.
Debian
CVE-2014-3562: 389-ds-base - Red Hat Directory Server 8 and 389 Directory Server, when debugging is enabled, ...
vendor_debian·2014·CVSS 5.0
CVE-2014-3562 [MEDIUM] CVE-2014-3562: 389-ds-base - Red Hat Directory Server 8 and 389 Directory Server, when debugging is enabled, ...
Red Hat Directory Server 8 and 389 Directory Server, when debugging is enabled, allows remote attackers to obtain sensitive replicated metadata by searching the directory.
Scope: local
bookworm: resolved (fixed in 1.3.2.21-1)
bullseye: resolved (fixed in 1.3.2.21-1)
sid: resolved (fixed in 1.3.2.21-1)
trixie: resolved (fixed in 1.3.2.21-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3562 389-ds-base: 389-ds: unauthenticated information disclosure [fedora-all]
bugzilla·2014-08-07·CVSS 5.0
CVE-2014-3562 [MEDIUM] CVE-2014-3562 389-ds-base: 389-ds: unauthenticated information disclosure [fedora-all]
CVE-2014-3562 389-ds-base: 389-ds: unauthenticated information disclosure [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported ver
Bugzilla
CVE-2014-3562 389-ds-base: 389-ds: unauthenticated information disclosure [epel-5]
bugzilla·2014-08-07·CVSS 5.0
CVE-2014-3562 [MEDIUM] CVE-2014-3562 389-ds-base: 389-ds: unauthenticated information disclosure [epel-5]
CVE-2014-3562 389-ds-base: 389-ds: unauthenticated information disclosure [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-5 tracking bug for 389-ds-base: see block
Bugzilla
CVE-2014-3562 389-ds: unauthenticated information disclosure
bugzilla·2014-07-25·CVSS 5.0
CVE-2014-3562 [MEDIUM] CVE-2014-3562 389-ds: unauthenticated information disclosure
CVE-2014-3562 389-ds: unauthenticated information disclosure
IssueDescription:
It was found that when replication was enabled for each attribute in Red Hat Directory Server / 389 Directory Server, which is the default configuration, the server returned replicated metadata when the directory was searched while debugging was enabled. A remote attacker could use this flaw to disclose potentially sensitive information.
Acknowledgements:
This issue was discovered by Ludwig Krispenz of Red Hat.
Discussion:
Created attachment 921040
patch to correct the flaw
---
Comment on attachment 921040
patch to correct the flaw
It would be better if the new int rootonly structure member were added at the end. This is a private structure, but just to be safe to ensure ABI compatibility.
Otherwise,
2014-08-21
Published