CVE-2015-1854
published 2017-09-19CVE-2015-1854: 389 Directory Server before 1.3.3.10 allows attackers to bypass intended access restrictions and modify directory entries via a crafted ldapmodrdn call.
PriorityP342high7.5CVSS 3.0
AVNACLPRNUINSUCNIHAN
EPSS
2.14%
80.0th percentile
389 Directory Server before 1.3.3.10 allows attackers to bypass intended access restrictions and modify directory entries via a crafted ldapmodrdn call.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | 389-ds-base | < 389-ds-base 1.3.3.10-1 (bookworm) | 389-ds-base 1.3.3.10-1 (bookworm) |
| debian | debian_linux | — | — |
| fedoraproject | 389_directory_server | <= 1.3.3.9 | — |
| fedoraproject | fedora | — | — |
| port389 | 389-ds-base | >= 0 < 1.3.3.10-1 | 1.3.3.10-1 |
| port389 | 389-ds-base | >= 0 < 1.3.3.10-1 | 1.3.3.10-1 |
| port389 | 389-ds-base | >= 0 < 1.3.3.10-1 | 1.3.3.10-1 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v685-gqm8-hvj7: 389 Directory Server before 1
ghsa_unreviewed·2022-05-14
CVE-2015-1854 [HIGH] CWE-284 GHSA-v685-gqm8-hvj7: 389 Directory Server before 1
389 Directory Server before 1.3.3.10 allows attackers to bypass intended access restrictions and modify directory entries via a crafted ldapmodrdn call.
OSV
CVE-2015-1854: 389 Directory Server before 1
osv·2017-09-19·CVSS 7.5
CVE-2015-1854 [HIGH] CVE-2015-1854: 389 Directory Server before 1
389 Directory Server before 1.3.3.10 allows attackers to bypass intended access restrictions and modify directory entries via a crafted ldapmodrdn call.
Red Hat
389-ds-base: access control bypass with modrdn
vendor_redhat·2015-04-28·CVSS 7.5
CVE-2015-1854 [HIGH] CWE-697 389-ds-base: access control bypass with modrdn
389-ds-base: access control bypass with modrdn
389 Directory Server before 1.3.3.10 allows attackers to bypass intended access restrictions and modify directory entries via a crafted ldapmodrdn call.
A flaw was found in the way Red Hat Directory Server performed authorization of modrdn operations. An unauthenticated attacker able to issue an ldapmodrdn call to the directory server could use this flaw to perform unauthorized modifications of entries in the directory server.
Statement: This issue does not affect the version of 389-ds-base package as shipped with Red Hat Enterprise Linux 6.
Package: redhat-ds-base (Red Hat Directory Server 8) - Not affected
Package: 389-ds-base (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2015-1854: 389-ds-base - 389 Directory Server before 1.3.3.10 allows attackers to bypass intended access ...
vendor_debian·2015·CVSS 7.5
CVE-2015-1854 [HIGH] CVE-2015-1854: 389-ds-base - 389 Directory Server before 1.3.3.10 allows attackers to bypass intended access ...
389 Directory Server before 1.3.3.10 allows attackers to bypass intended access restrictions and modify directory entries via a crafted ldapmodrdn call.
Scope: local
bookworm: resolved (fixed in 1.3.3.10-1)
bullseye: resolved (fixed in 1.3.3.10-1)
sid: resolved (fixed in 1.3.3.10-1)
trixie: resolved (fixed in 1.3.3.10-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-1854 389-ds-base: access control bypass with modrdn [fedora-all]
bugzilla·2015-04-28·CVSS 7.5
CVE-2015-1854 [HIGH] CVE-2015-1854 389-ds-base: access control bypass with modrdn [fedora-all]
CVE-2015-1854 389-ds-base: access control bypass with modrdn [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedo
Bugzilla
CVE-2015-1854 389-ds-base: access control bypass with modrdn
bugzilla·2015-04-07·CVSS 7.5
CVE-2015-1854 [HIGH] CVE-2015-1854 389-ds-base: access control bypass with modrdn
CVE-2015-1854 389-ds-base: access control bypass with modrdn
An access control bypass flaw was found in modrdn. In particular if a user has a rdn like uid=username, then the user can change its own rdn to any value that is a superstring of the current name bypassing access control.
This issue could be reproduced by the following:
ldapmodrnd -Y GSSAPI -r uid=testuser,cn=users,cn=accounts,dc=test,dc=ipa uid=testuser_extended_without_permission
The above succeeds and renames the user.
No authentication whatsoever is necessary. An anonymous user can completely hose a server (if not worse) by just renaming any entry it pleases.
If ACIs are employed to hide entries and those entries are targeted by
name then it is also possible to reveal those contents by renaming the
entry and falling off
http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157069.htmlhttp://www.securityfocus.com/bid/74392https://access.redhat.com/errata/RHSA-2015:0895https://bugzilla.redhat.com/show_bug.cgi?id=1209573https://lists.debian.org/debian-lts-announce/2018/07/msg00018.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-May/157069.htmlhttp://www.securityfocus.com/bid/74392https://access.redhat.com/errata/RHSA-2015:0895https://bugzilla.redhat.com/show_bug.cgi?id=1209573https://lists.debian.org/debian-lts-announce/2018/07/msg00018.html
2017-09-19
Published