Your message dated Mon, 8 Jan 2024 18:14:06 +0200
with message-id <[email protected]>
and subject line Re: [Pkg-freeipa-devel] Bug#1034891: 389-ds-base: CVE-2023-1055
has caused the Debian Bug report #1034891,
regarding 389-ds-base: CVE-2023-1055
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1034891: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1034891
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: 389-ds-base
X-Debbugs-CC: [email protected]
Severity: important
Tags: security

Hi,

The following vulnerability was published for 389-ds-base.

CVE-2023-1055[0]:
| A flaw was found in RHDS 11 and RHDS 12. While browsing entries LDAP
| tries to decode the userPassword attribute instead of the
| userCertificate attribute which could lead into sensitive information
| leaked. An attacker with a local account where the cockpit-389-ds is
| running can list the processes and display the hashed passwords. The
| highest threat from this vulnerability is to data confidentiality.

https://bugzilla.redhat.com/show_bug.cgi?id=2173517

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2023-1055
    https://www.cve.org/CVERecord?id=CVE-2023-1055

Please adjust the affected versions in the BTS as needed.

--- End Message ---
--- Begin Message ---
Source: 389-ds-base
Version: 2.3.4+dfsg1-1

Moritz Mühlenhoff kirjoitti 26.4.2023 klo 20.43:
Source: 389-ds-base
X-Debbugs-CC: [email protected]
Severity: important
Tags: security

Hi,

The following vulnerability was published for 389-ds-base.

CVE-2023-1055[0]:
| A flaw was found in RHDS 11 and RHDS 12. While browsing entries LDAP
| tries to decode the userPassword attribute instead of the
| userCertificate attribute which could lead into sensitive information
| leaked. An attacker with a local account where the cockpit-389-ds is
| running can list the processes and display the hashed passwords. The
| highest threat from this vulnerability is to data confidentiality.

https://bugzilla.redhat.com/show_bug.cgi?id=2173517

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2023-1055
     https://www.cve.org/CVERecord?id=CVE-2023-1055

Please adjust the affected versions in the BTS as needed.

this was fixed upstream in 2.3.2


--
t

--- End Message ---

Reply via email to