CVE-2016-5405
published 2017-06-08CVE-2016-5405: 389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server 6 through…
PriorityP350critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
3.06%
86.2th percentile
389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server 6 through 7, and Red Hat Enterprise Linux Workstation 6 through 7 allows remote attackers to obtain user passwords.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | 389-ds-base | < 389-ds-base 1.3.5.15-1 (bookworm) | 389-ds-base 1.3.5.15-1 (bookworm) |
| port389 | 389-ds-base | >= 0 < 1.3.5.15-1 | 1.3.5.15-1 |
| port389 | 389-ds-base | >= 0 < 1.3.5.15-1 | 1.3.5.15-1 |
| port389 | 389-ds-base | >= 0 < 1.3.5.15-1 | 1.3.5.15-1 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_hpc_node | — | — |
| redhat | enterprise_linux_hpc_node | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3mg8-mw7w-wg96: 389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server 6
ghsa_unreviewed·2022-05-17
CVE-2016-5405 [CRITICAL] GHSA-3mg8-mw7w-wg96: 389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server 6
389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server 6 through 7, and Red Hat Enterprise Linux Workstation 6 through 7 allows remote attackers to obtain user passwords.
OSV
CVE-2016-5405: 389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server 6
osv·2017-06-08·CVSS 9.8
CVE-2016-5405 [CRITICAL] CVE-2016-5405: 389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server 6
389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server 6 through 7, and Red Hat Enterprise Linux Workstation 6 through 7 allows remote attackers to obtain user passwords.
Red Hat
389-ds-base: Password verification vulnerable to timing attack
vendor_redhat·2016-10-26·CVSS 9.8
CVE-2016-5405 [CRITICAL] CWE-385 389-ds-base: Password verification vulnerable to timing attack
389-ds-base: Password verification vulnerable to timing attack
389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server 6 through 7, and Red Hat Enterprise Linux Workstation 6 through 7 allows remote attackers to obtain user passwords.
It was found that 389 Directory Server was vulnerable to a remote password disclosure via timing attack. A remote attacker could possibly use this flaw to retrieve directory server password after many tries.
Package: redhat-ds-base (Red Hat Directory Server 8) - Will not fix
Debian
CVE-2016-5405: 389-ds-base - 389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat En...
vendor_debian·2016·CVSS 9.8
CVE-2016-5405 [CRITICAL] CVE-2016-5405: 389-ds-base - 389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat En...
389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server 6 through 7, and Red Hat Enterprise Linux Workstation 6 through 7 allows remote attackers to obtain user passwords.
Scope: local
bookworm: resolved (fixed in 1.3.5.15-1)
bullseye: resolved (fixed in 1.3.5.15-1)
sid: resolved (fixed in 1.3.5.15-1)
trixie: resolved (fixed in 1.3.5.15-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-15041 389-ds-base: 389-ds-base: Non-constant-time comparison in PBKDF2-SHA256 password verification [fedora-all]
bugzilla·2026-07-08·CVSS 9.8
CVE-2026-15041 [CRITICAL] CVE-2026-15041 389-ds-base: 389-ds-base: Non-constant-time comparison in PBKDF2-SHA256 password verification [fedora-all]
CVE-2026-15041 389-ds-base: 389-ds-base: Non-constant-time comparison in PBKDF2-SHA256 password verification [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password verification function pbkdf2_sha256_pw_cmp() in ldap/servers/plugins/pwdstorage/pbkdf2_pwd.c uses standard memcmp() for hash comparison instead of the project's constant-time slapi_ct_memcmp(). Every other password storage scheme in the same plugin uses slapi_ct_memcmp(), which was introduced specifically to prevent timing side-channels (see CVE-2016-5405). This inconsistency allo
Bugzilla
CVE-2026-15041 389-ds-base: 389-ds-base: Non-constant-time comparison in PBKDF2-SHA256 password verification
bugzilla·2026-07-08·CVSS 9.8
CVE-2026-15041 [CRITICAL] CVE-2026-15041 389-ds-base: 389-ds-base: Non-constant-time comparison in PBKDF2-SHA256 password verification
CVE-2026-15041 389-ds-base: 389-ds-base: Non-constant-time comparison in PBKDF2-SHA256 password verification
A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password verification function pbkdf2_sha256_pw_cmp() in ldap/servers/plugins/pwdstorage/pbkdf2_pwd.c uses standard memcmp() for hash comparison instead of the project's constant-time slapi_ct_memcmp(). Every other password storage scheme in the same plugin uses slapi_ct_memcmp(), which was introduced specifically to prevent timing side-channels (see CVE-2016-5405). This inconsistency allows a remote attacker with network access to the LDAP service to potentially infer partial hash information through repeated timing measurements of LDAP bind attempts. Practical exploitation is extremely difficult due to the PBKDF2 work fa
Bugzilla
CVE-2017-15135 389-ds-base: Authentication bypass due to lack of size check in slapi_ct_memcmp function in ch_malloc.c
bugzilla·2017-12-13·CVSS 9.8
CVE-2017-15135 [CRITICAL] CVE-2017-15135 389-ds-base: Authentication bypass due to lack of size check in slapi_ct_memcmp function in ch_malloc.c
CVE-2017-15135 389-ds-base: Authentication bypass due to lack of size check in slapi_ct_memcmp function in ch_malloc.c
A flaw was found in 389-ds-base that was introduced after CVE-2016-5405 fix. A lack of size check in slapi_ct_memcmp() function may lead to authentication bypass through pre-hashed userPassword attributes under highly specific circumstances.
Discussion:
Acknowledgments:
Name: Martin Poole (Red Hat)
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2018:0414 https://access.redhat.com/errata/RHSA-2018:0414
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2018:0515 https://access.redhat.com/errata/RHSA-2018:0515
---
This bug is now closed. Further updates for individua
Bugzilla
CVE-2016-5405 389-ds-base: Password verification vulnerable to timing attack
bugzilla·2016-07-21·CVSS 9.8
CVE-2016-5405 [CRITICAL] CVE-2016-5405 389-ds-base: Password verification vulnerable to timing attack
CVE-2016-5405 389-ds-base: Password verification vulnerable to timing attack
It was found that 389 Directory Server is vulnerable to a remote password disclosure via timing attack. Due to the use of strcmp and memcmp in the verification of passwords and hashes, remote attacker is able to tell the difference between computation times which makes him able to retrieve the password after many tries.
This affects systems storing passwords in plain text. Systems using unsalted hashes might be unsafe as well if using weak hash algorithms, however the attack would be very time-consuming.
Discussion:
Acknowledgments:
Name: William Brown (Red Hat)
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2016:2594 https://rhn.redhat.com/errata/RHSA-201
http://rhn.redhat.com/errata/RHSA-2016-2594.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2765.htmlhttp://www.securityfocus.com/bid/93884https://bugzilla.redhat.com/show_bug.cgi?id=1358865http://rhn.redhat.com/errata/RHSA-2016-2594.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2765.htmlhttp://www.securityfocus.com/bid/93884https://bugzilla.redhat.com/show_bug.cgi?id=1358865
2017-06-08
Published