mailing list archives
CVE Request -- 389-ds-base: Change on SLAPI_MODRDN_NEWSUPERIOR is not evaluated in ACL (ACL rules bypass possible)
From: Jan Lieskovsky <jlieskov () redhat com>
Date: Wed, 26 Sep 2012 05:54:13 -0400 (EDT)
Hello Kurt, Steve, vendors,
Noriko Hosoi of Red Hat notified us about the following deficiency:
A possibility to bypass access control list (ACL) definitions was found
in the way 389 Directory Server performed LDAP modifyRDN operation upon
request from client. When a user has been granted access to set of DN
entries, but denied access to a specific subset of those entries, it
was possible the user to obtain temporary (till next Directory Server
restart) access to that subset of entries (they should not have had
otherwise ability to access) when the DN entry was moved via database
modify RDN function.
Relevant upstream patch:
Could you allocate a CVE id for this?
Thank you && Regards, Jan.
Jan iankko Lieskovsky / Red Hat Security Response Team
- CVE Request -- 389-ds-base: Change on SLAPI_MODRDN_NEWSUPERIOR is not evaluated in ACL (ACL rules bypass possible) Jan Lieskovsky (Sep 26)