Information disclosure in 389-ds-base - CVE-2020-35518
Published: June 15, 2021
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application. When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be used by an unauthenticated attacker to check the existence of an entry in the LDAP database.
Affected software
Red Hat Directory Server
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
CentOS
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
SUSE Linux Enterprise Module for Server Applications
openEuler
Fedora
389-ds-base (Red Hat package)
python3-lib389
389-ds-base-snmp
389-ds-base-libs
389-ds-base-legacy-tools
389-ds-base-devel
389-ds-base
389-ds
389-ds-debuginfo
389-ds-debugsource
389-ds-devel
lib389
libsvrcore0
libsvrcore0-debuginfo
389-ds-base-debuginfo
389-ds-base-debugsource
389-ds-base-help
cockpit-389-ds
freeipa
dogtag-pki
pki-core
How to mitigate CVE-2020-35518
389-ds-base (Red Hat package) - update to 1.3.10.2-12.el7_9
python3-lib389 - update to 1.4.2.4-13
389-ds-base-snmp - update to 1.4.2.4-13
389-ds-base-libs - update to 1.4.2.4-13
389-ds-base-legacy-tools - update to 1.4.2.4-13
389-ds-base-devel - update to 1.4.2.4-13
389-ds-base - update to 1.4.2.4-13
389-ds - update to 1.4.3.19~git0.bef0b5bed-3.12.1
389-ds-debuginfo - update to 1.4.3.19~git0.bef0b5bed-3.12.1
389-ds-debugsource - update to 1.4.3.19~git0.bef0b5bed-3.12.1
389-ds-devel - update to 1.4.3.19~git0.bef0b5bed-3.12.1
lib389 - update to 1.4.3.19~git0.bef0b5bed-3.12.1
libsvrcore0 - update to 1.4.3.19~git0.bef0b5bed-3.12.1
libsvrcore0-debuginfo - update to 1.4.3.19~git0.bef0b5bed-3.12.1
389-ds-base - addressed in versions 1.4.3.19-1.fc32, 1.4.3.20-2.fc32, 1.4.4.13-2.fc33, 2.0.3-3.fc34
python3-lib389 - update to 1.4.3.20-1
389-ds-base-devel - update to 1.4.3.20-1
389-ds-base-snmp - update to 1.4.3.20-1
389-ds-base-debuginfo - update to 1.4.3.20-1
389-ds-base-debugsource - update to 1.4.3.20-1
389-ds-base-help - update to 1.4.3.20-1
389-ds-base-legacy-tools - update to 1.4.3.20-1
389-ds-base - update to 1.4.3.20-1
cockpit-389-ds - update to 1.4.3.20-1
freeipa - addressed in versions 4.9.2-4.fc32, 4.9.2-4.fc33, 4.9.2-4.fc34
dogtag-pki - addressed in versions 10.10.5-1.fc32, 10.10.5-1.fc33, 10.10.5-1.fc34
pki-core - addressed in versions 10.10.5-1.fc32, 10.10.5-1.fc33, 10.10.5-1.fc34
External References
Related Security Bulletins
- Information disclosure in 389-ds-base
- CentOS 7 update for 389-ds-base
- Red Hat Enterprise Linux 7 update for 389-ds-base
- SUSE update for 389-ds
- openEuler update for three-eight-nine-ds-base
- openEuler 22.03 LTS update for three-eight-nine-ds-base
- Red Hat Directory Server 11 update for the redhat-ds:11 module
- Red Hat Enterprise Linux 8 update for the 389-ds:1.4 module
- Red Hat Directory Server 11 update for the redhat-ds:11 module
- Red Hat Enterprise Linux 8 update for the 389-ds:1.4 module
- Fedora 32 update for 389-ds-base
- Fedora 34 update for 389-ds-base, dogtag-pki, freeipa, pki-core
- Fedora 33 update for 389-ds-base, dogtag-pki, freeipa, pki-core
- Fedora 32 update for 389-ds-base, dogtag-pki, freeipa, pki-core
- Anolis OS update for 389-ds:1.4 module