CVE-2017-7551
published 2017-08-16CVE-2017-7551: 389-ds-base version before 1.3.5.19 and 1.3.6.7 are vulnerable to password brute-force attacks during account lockout due to different return codes returned on…
PriorityP342critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
1.42%
69.9th percentile
389-ds-base version before 1.3.5.19 and 1.3.6.7 are vulnerable to password brute-force attacks during account lockout due to different return codes returned on password attempts.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| 389_directory_server | 389-ds-base | — | — |
| debian | 389-ds-base | < 389-ds-base 1.3.6.7-1 (bookworm) | 389-ds-base 1.3.6.7-1 (bookworm) |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| port389 | 389-ds-base | >= 0 < 1.3.6.7-1 | 1.3.6.7-1 |
| port389 | 389-ds-base | >= 0 < 1.3.6.7-1 | 1.3.6.7-1 |
| port389 | 389-ds-base | >= 0 < 1.3.6.7-1 | 1.3.6.7-1 |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rr4q-qmwm-h86v: 389-ds-base version before 1
ghsa_unreviewed·2022-05-14
CVE-2017-7551 [CRITICAL] CWE-209 GHSA-rr4q-qmwm-h86v: 389-ds-base version before 1
389-ds-base version before 1.3.5.19 and 1.3.6.7 are vulnerable to password brute-force attacks during account lockout due to different return codes returned on password attempts.
OSV
CVE-2017-7551: 389-ds-base version before 1
osv·2017-08-16·CVSS 9.8
CVE-2017-7551 [CRITICAL] CVE-2017-7551: 389-ds-base version before 1
389-ds-base version before 1.3.5.19 and 1.3.6.7 are vulnerable to password brute-force attacks during account lockout due to different return codes returned on password attempts.
Red Hat
389-ds-base: Password brute-force possible for locked account due to different return codes
vendor_redhat·2017-07-31·CVSS 9.8
CVE-2017-7551 [CRITICAL] CWE-209 389-ds-base: Password brute-force possible for locked account due to different return codes
389-ds-base: Password brute-force possible for locked account due to different return codes
389-ds-base version before 1.3.5.19 and 1.3.6.7 are vulnerable to password brute-force attacks during account lockout due to different return codes returned on password attempts.
A flaw was found in the way 389-ds-base handled authentication attempts against locked accounts. A remote attacker could potentially use this flaw to continue password brute-forcing attacks against LDAP accounts, thereby bypassing the protection offered by the directory server's password lockout policy.
Package: 389-ds-base (Red Hat Enterprise Linux 6) - Will not fix
Debian
CVE-2017-7551: 389-ds-base - 389-ds-base version before 1.3.5.19 and 1.3.6.7 are vulnerable to password brute...
vendor_debian·2017·CVSS 9.8
CVE-2017-7551 [CRITICAL] CVE-2017-7551: 389-ds-base - 389-ds-base version before 1.3.5.19 and 1.3.6.7 are vulnerable to password brute...
389-ds-base version before 1.3.5.19 and 1.3.6.7 are vulnerable to password brute-force attacks during account lockout due to different return codes returned on password attempts.
Scope: local
bookworm: resolved (fixed in 1.3.6.7-1)
bullseye: resolved (fixed in 1.3.6.7-1)
sid: resolved (fixed in 1.3.6.7-1)
trixie: resolved (fixed in 1.3.6.7-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-7551 389-ds-base: Password brute-force possible for locked account due to different return codes [fedora-all]
bugzilla·2017-08-02·CVSS 9.8
CVE-2017-7551 [CRITICAL] CVE-2017-7551 389-ds-base: Password brute-force possible for locked account due to different return codes [fedora-all]
CVE-2017-7551 389-ds-base: Password brute-force possible for locked account due to different return codes [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this
Bugzilla
CVE-2017-7551 389-ds-base: Password brute-force possible for locked account due to different return codes
bugzilla·2017-08-02·CVSS 9.8
CVE-2017-7551 [CRITICAL] CVE-2017-7551 389-ds-base: Password brute-force possible for locked account due to different return codes
CVE-2017-7551 389-ds-base: Password brute-force possible for locked account due to different return codes
The directory server password lockout policy prevents binds from operating once a threshold of failed passwords has been met. If attacker during this lockout binds with the correct password, a different error code is returned. This means that attacker has no ratelimit or penalty during the account lock, and can continue to attempt passwords via bruteforce.
Upstream bug:
https://pagure.io/389-ds-base/issue/49336
Upstream patch:
https://pagure.io/389-ds-base/c/33db32a3e14b849d
Discussion:
Created 389-ds-base tracking bugs for this issue:
Affects: fedora-all [bug 1477674]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2017:2569
2017-08-16
Published