CVE-2016-8750
published 2018-02-19CVE-2016-8750: Apache Karaf prior to 4.0.8 used the LDAPLoginModule to authenticate users to a directory via LDAP. However, it did not encoding usernames properly and hence…
PriorityP434medium6.5CVSS 3.0
AVNACLPRLUINSUCNINAH
EPSS
5.28%
91.6th percentile
Apache Karaf prior to 4.0.8 used the LDAPLoginModule to authenticate users to a directory via LDAP. However, it did not encoding usernames properly and hence was vulnerable to LDAP injection attacks leading to a denial of service.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | karaf | < 4.0.8 | 4.0.8 |
| apache_software_foundation | apache_karaf | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
karaf: LDAP injection in LDAPLoginModule
vendor_redhat·2016-12-12·CVSS 6.5
CVE-2016-8750 [MEDIUM] CWE-90 karaf: LDAP injection in LDAPLoginModule
karaf: LDAP injection in LDAPLoginModule
Apache Karaf prior to 4.0.8 used the LDAPLoginModule to authenticate users to a directory via LDAP. However, it did not encoding usernames properly and hence was vulnerable to LDAP injection attacks leading to a denial of service.
Apache Karaf uses the LDAPLoginModule to authenticate users to a directory via LDAP. It does not, however, encode usernames properly and hence is vulnerable to LDAP injection attacks. While it appears that it is not possible to exploit this vulnerability to allow an attacker to gain remote access, it does allow an attacker to insert special characters into the search query step. Therefore, it can potentially be exploited as part of a Denial of Service attack.
Package: karaf (Red Hat JBoss A-MQ 6) - Affected
Package: op
GHSA
Moderate severity vulnerability that affects org.apache.karaf:apache-karaf
ghsa·2019-01-07
CVE-2016-8750 [MEDIUM] CWE-90 Moderate severity vulnerability that affects org.apache.karaf:apache-karaf
Moderate severity vulnerability that affects org.apache.karaf:apache-karaf
Apache Karaf prior to 4.0.8 used the LDAPLoginModule to authenticate users to a directory via LDAP. However, it did not encoding usernames properly and hence was vulnerable to LDAP injection attacks leading to a denial of service.
OSV
Moderate severity vulnerability that affects org.apache.karaf:apache-karaf
osv·2019-01-07
CVE-2016-8750 [MEDIUM] Moderate severity vulnerability that affects org.apache.karaf:apache-karaf
Moderate severity vulnerability that affects org.apache.karaf:apache-karaf
Apache Karaf prior to 4.0.8 used the LDAPLoginModule to authenticate users to a directory via LDAP. However, it did not encoding usernames properly and hence was vulnerable to LDAP injection attacks leading to a denial of service.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-8750 karaf: LDAP injection in LDAPLoginModule
bugzilla·2017-12-11·CVSS 6.5
CVE-2016-8750 [MEDIUM] CVE-2016-8750 karaf: LDAP injection in LDAPLoginModule
CVE-2016-8750 karaf: LDAP injection in LDAPLoginModule
Apache Karaf uses the LDAPLoginModule to authenticate users to a directory
via LDAP. However, it is not encoding usernames properly and hence is
vulnerable to LDAP injection attacks.
While it appears that it not possible to exploit this vulnerability to allow
an attacker to gain remote access, it allows an attacker to insert special
characters into the search query step. Therefore, it can potentially be
exploited as part of a Denial Of Service attack.
External References:
https://karaf.apache.org/security/cve-2016-8750.txt
Upstream patch:
https://github.com/apache/karaf/commit/ac07cb2440ceff94b3001728c1611fc471253d19
Discussion:
This issue has been addressed in the following products:
Red Hat JBoss Fuse
Via RHSA-2018:1322 htt
Bugzilla
CVE-2015-8750 libdwarf: NULL pointer dereference in dwarf_utils.c
bugzilla·2016-01-08·CVSS 6.5
CVE-2015-8750 [MEDIUM] CVE-2015-8750 libdwarf: NULL pointer dereference in dwarf_utils.c
CVE-2015-8750 libdwarf: NULL pointer dereference in dwarf_utils.c
A null pointer dereference was found in the libdwarf package. This flaw may result in a crash with specially crafted input.
This was originally filed as bug 1294264.
CVE assignment:
http://seclists.org/oss-sec/2016/q1/45
Upstream patch:
11750a2838e52953013e3114ef27b3c7b1780697
in
git://git.code.sf.net/p/libdwarf/code
Also available on GitHub:
https://github.com/tomhughes/libdwarf/commit/11750a2838e52953013e3114ef27b3c7b1780697
Discussion:
Created libdwarf tracking bugs for this issue:
Affects: epel-6 [bug 1296989]
---
BTW my github repo is not the upstream... The upstream is the repo at git://git.code.sf.net/p/libdwarf/code.
---
(In reply to Tom Hughes from comment #2)
> BTW my github repo is not the upstream.
2018-02-19
Published