Bug 997256 (CVE-2016-4992) - VUL-0: CVE-2016-4992: 389-ds: Information disclosure via repeated use of LDAP ADD operation
Summary: VUL-0: CVE-2016-4992: 389-ds: Information disclosure via repeated use of LDAP...
Status: RESOLVED FIXED
Alias: CVE-2016-4992
Product: openSUSE Distribution
Classification: openSUSE
Component: Security (show other bugs)
Version: Leap 42.3
Hardware: Other Other
: P3 - Medium : Minor (vote)
Target Milestone: ---
Assignee: Security Team bot
QA Contact: E-mail List
URL: https://smash.suse.de/issue/170279/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2016-09-05 14:08 UTC by Andreas Stieger
Modified: 2018-01-09 13:50 UTC (History)
6 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Andreas Stieger 2016-09-05 14:08:30 UTC
http://directory.fedoraproject.org/docs/389ds/releases/release-1-3-5-13.html

Detailed Changelog since 1.3.5.4

    CVE-2016-4992 389-ds-base: Information disclosure via repeated use of LDAP ADD operation, etc.

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1347760
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-4992
http://people.canonical.com/~ubuntu-security/cve/2016/CVE-2016-4992.html
Comment 1 Marcus Rückert 2016-09-05 14:11:01 UTC
note there is also a mention of tmp file bugs metioned in the change log at http://directory.fedoraproject.org/docs/389ds/releases/release-1-3-5-13.html
Comment 2 Swamp Workflow Management 2016-09-05 22:01:59 UTC
bugbot adjusting priority
Comment 4 Andreas Stieger 2017-11-20 22:39:21 UTC
Howard, could I bother you for a maintenance update for Leap for these bugs?
991201,997256,1007004,1020670,1051997,1069067,1069074
Comment 5 Bernhard Wiedemann 2017-12-05 11:40:25 UTC
This is an autogenerated message for OBS integration:
This bug (997256) was mentioned in
https://build.opensuse.org/request/show/548604 42.2 / 389-ds
Comment 6 Bernhard Wiedemann 2017-12-06 14:40:23 UTC
This is an autogenerated message for OBS integration:
This bug (997256) was mentioned in
https://build.opensuse.org/request/show/554810 42.2 / 389-ds
Comment 7 Andreas Stieger 2017-12-18 20:46:09 UTC
releasing, done. Thanks Howard
Comment 8 Swamp Workflow Management 2017-12-19 02:07:59 UTC
openSUSE-SU-2017:3362-1: An update that solves four vulnerabilities and has two fixes is now available.

Category: security (moderate)
Bug References: 1007004,1020670,1051997,1069067,1069074,997256
CVE References: CVE-2016-4992,CVE-2016-5405,CVE-2017-2668,CVE-2017-7551
Sources used:
openSUSE Leap 42.3 (src):    389-ds-1.3.4.5-8.1
openSUSE Leap 42.2 (src):    389-ds-1.3.4.5-5.5.1
Comment 9 Karol Babioch 2018-01-09 13:50:32 UTC
All updates released.