Bug 1730477 (CVE-2019-13565) - CVE-2019-13565 openldap: ACL restrictions bypass due to sasl_ssf value being set permanently
Summary: CVE-2019-13565 openldap: ACL restrictions bypass due to sasl_ssf value being ...
Keywords:
Status: NEW
Alias: CVE-2019-13565
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1738898 1738926 1740758
Blocks: 1730478
TreeView+ depends on / blocked
 
Reported: 2019-07-16 20:10 UTC by Pedro Sampaio
Modified: 2019-12-12 07:18 UTC (History)
37 users (show)

Fixed In Version: openldap 2.4.48
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed:


Attachments (Terms of Use)

Description Pedro Sampaio 2019-07-16 20:10:47 UTC
A flaw was found in OpenLDAP before version 2.4.48. An improper authorization issue in cyrus-sasl based SASL mechanisms may lead to ACL bypass.

References:

https://bugzilla.redhat.com/show_bug.cgi?id=1728902

Comment 1 Joshua Padman 2019-08-06 05:33:36 UTC
This vulnerability is out of security support scope for the following product:
 * Red Hat Enterprise Application Platform 5
 * Red Hat JBoss Web Server 2 
 * Red Hat JBoss Core Services

Please refer to https://access.redhat.com/support/policy/updates/jboss_notes for more details.

Comment 3 Stefan Cornelius 2019-08-08 11:37:10 UTC
Created openldap tracking bugs for this issue:

Affects: fedora-all [bug 1738898]

Comment 7 Stefan Cornelius 2019-08-14 16:35:52 UTC
Statement:

This issue affects the versions of openldap as shipped with Red Hat Enterprise Linux 5, 6, 7, and 8.

Red Hat Enterprise Linux 5 is now in Extended Life Phase of the support and maintenance life cycle. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.

Red Hat Enterprise Linux 6 is now in Maintenance Support 2 Phase of the support and maintenance life cycle. This has been rated as having a security impact of Moderate, and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.


Note You need to log in before you can comment on or make changes to this bug.