[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248364

 
 

909

 
 

195388

 
 

282

Paid content will be excluded from the download.


Download | Alert*


CVE-2014-8112
389 Directory Server 1.3.1.x, 1.3.2.x before 1.3.2.27, and 1.3.3.x before 1.3.3.9 stores "unhashed" passwords even when the nsslapd-unhashed-pw-switch option is set to off, which allows remote authenticated users to obtain sensitive information by reading the Changelog.

CVE-2014-8105
389 Directory Server before 1.3.2.27 and 1.3.3.x before 1.3.3.9 does not properly restrict access to the "cn=changelog" LDAP sub-tree, which allows remote attackers to obtain sensitive information from the changelog via unspecified vectors.

*OVAL
oval:org.secpod.oval:def:501513
CPE    45
cpe:/a:fedoraproject:389_directory_server
cpe:/a:fedoraproject:389_directory_server:1.3.2.11
cpe:/a:fedoraproject:389_directory_server:1.3.1.22
cpe:/a:fedoraproject:389_directory_server:1.3.2.10
...

© SecPod Technologies