Red Hat Bugzilla – Bug 1525628
CVE-2017-15135 389-ds-base: Authentication bypass due to lack of size check in slapi_ct_memcmp function in ch_malloc.c
Last modified: 2018-04-20 09:07:34 EDT
A flaw was found in 389-ds-base that was introduced after CVE-2016-5405 fix. A lack of size check in slapi_ct_memcmp() function may lead to authentication bypass through pre-hashed userPassword attributes under highly specific circumstances.
Acknowledgments: Name: Martin Poole (Red Hat)
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2018:0414 https://access.redhat.com/errata/RHSA-2018:0414
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Via RHSA-2018:0515 https://access.redhat.com/errata/RHSA-2018:0515