389 Directory Server 1.2.10 does not properly update the ACL when a DN entry is moved by a modrdn operation, which allows remote authenticated users with certain permissions to bypass ACL restrictions and access the DN entry.
Name | Vendor | Start Version | End Version |
---|---|---|---|
389_directory_server | Fedoraproject | 1.2.10 (including) | 1.2.10 (including) |
Red Hat Enterprise Linux 6 | RedHat | 389-ds-base-0:1.2.11.15-11.el6 | * |
389-ds-base | Ubuntu | precise | * |
389-ds-base | Ubuntu | quantal | * |
389-ds-base | Ubuntu | upstream | * |