CVE Vulnerabilities

CVE-2014-0132

Improper Authentication

Published: Mar 18, 2014 | Modified: Feb 13, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
6.5 IMPORTANT
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V3
Ubuntu
HIGH

The SASL authentication functionality in 389 Directory Server before 1.2.11.26 allows remote authenticated users to connect as an arbitrary user and gain privileges via the authzid parameter in a SASL/GSSAPI bind.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
389_directory_server Fedoraproject * 1.2.11.25 (including)
389_directory_server Fedoraproject 1.2.11.1 (including) 1.2.11.1 (including)
389_directory_server Fedoraproject 1.2.11.5 (including) 1.2.11.5 (including)
389_directory_server Fedoraproject 1.2.11.6 (including) 1.2.11.6 (including)
389_directory_server Fedoraproject 1.2.11.8 (including) 1.2.11.8 (including)
389_directory_server Fedoraproject 1.2.11.9 (including) 1.2.11.9 (including)
389_directory_server Fedoraproject 1.2.11.10 (including) 1.2.11.10 (including)
389_directory_server Fedoraproject 1.2.11.11 (including) 1.2.11.11 (including)
389_directory_server Fedoraproject 1.2.11.12 (including) 1.2.11.12 (including)
389_directory_server Fedoraproject 1.2.11.13 (including) 1.2.11.13 (including)
389_directory_server Fedoraproject 1.2.11.14 (including) 1.2.11.14 (including)
389_directory_server Fedoraproject 1.2.11.15 (including) 1.2.11.15 (including)
389_directory_server Fedoraproject 1.2.11.17 (including) 1.2.11.17 (including)
389_directory_server Fedoraproject 1.2.11.19 (including) 1.2.11.19 (including)
389_directory_server Fedoraproject 1.2.11.20 (including) 1.2.11.20 (including)
389_directory_server Fedoraproject 1.2.11.21 (including) 1.2.11.21 (including)
389_directory_server Fedoraproject 1.2.11.22 (including) 1.2.11.22 (including)
389_directory_server Fedoraproject 1.2.11.23 (including) 1.2.11.23 (including)
389-ds-base Ubuntu precise *
389-ds-base Ubuntu quantal *
389-ds-base Ubuntu saucy *
389-ds-base Ubuntu upstream *
Red Hat Enterprise Linux 6 RedHat 389-ds-base-0:1.2.11.15-32.el6_5 *

Potential Mitigations

References