389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server 6 through 7, and Red Hat Enterprise Linux Workstation 6 through 7 allows remote attackers to obtain user passwords.
References
Link | Resource |
---|---|
http://rhn.redhat.com/errata/RHSA-2016-2594.html | Vendor Advisory |
http://rhn.redhat.com/errata/RHSA-2016-2765.html | Vendor Advisory |
http://www.securityfocus.com/bid/93884 | Third Party Advisory VDB Entry |
https://bugzilla.redhat.com/show_bug.cgi?id=1358865 | Issue Tracking Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
12 Feb 2023, 23:24
Type | Values Removed | Values Added |
---|---|---|
Summary | 389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server 6 through 7, and Red Hat Enterprise Linux Workstation 6 through 7 allows remote attackers to obtain user passwords. | |
References |
|
02 Feb 2023, 15:17
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Summary | It was found that 389 Directory Server was vulnerable to a remote password disclosure via timing attack. A remote attacker could possibly use this flaw to retrieve directory server password after many tries. |
Information
Published : 2017-06-08 19:29
Updated : 2023-12-10 12:15
NVD link : CVE-2016-5405
Mitre link : CVE-2016-5405
CVE.ORG link : CVE-2016-5405
JSON object : View
Products Affected
redhat
- enterprise_linux_hpc_node
- enterprise_linux_server
- enterprise_linux_desktop
- enterprise_linux_workstation
CWE
CWE-199
Information Management Errors