Bug 991201 (CVE-2016-5416) - VUL-0: CVE-2016-5416: 389-ds: ACI readable by anonymous user
Summary: VUL-0: CVE-2016-5416: 389-ds: ACI readable by anonymous user
Status: RESOLVED FIXED
Alias: CVE-2016-5416
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other openSUSE 42.1
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/171458/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2016-07-29 08:10 UTC by Andreas Stieger
Modified: 2020-04-11 22:50 UTC (History)
6 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Andreas Stieger 2016-07-29 08:10:12 UTC
Via RH: It was found that 389 Directory Server is vulnerable to a flaw in which the default ACI (Access control instructions) could be read by an anonymous user. This could lead to leakage to sensitive information.

https://fedorahosted.org/389/ticket/48852

I guess this will be included in a future version, and if anything this look like a configuration issue and improvements of a default / addition of configuration options less prone to misconfiguration?

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1349540
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-5416
Comment 1 Swamp Workflow Management 2016-07-29 22:00:15 UTC
bugbot adjusting priority
Comment 2 Andreas Stieger 2016-09-05 14:09:20 UTC
ping, along with bug 997256?
Comment 3 Andreas Stieger 2017-11-20 22:39:19 UTC
Howard, could I bother you for a maintenance update for Leap for these bugs?
991201,997256,1007004,1020670,1051997,1069067,1069074
Comment 4 Howard Guo 2017-12-05 10:21:54 UTC
As of today, the upstream developers do not have a resolution to this issue according to https://pagure.io/389-ds-base/issue/48852
Comment 5 Alexander Bergmann 2019-04-15 15:27:58 UTC
According to the RHSA[1] this is already fixed in the current version.

@William: Could you double check and reassign to security?

[1] https://access.redhat.com/errata/RHSA-2016:2594
Comment 6 William Brown 2019-04-16 01:00:56 UTC
This ticket confuses two issues IMO. First is the ticket about the targetaci issue - that's not a cve and is just something that can't be fixed.

The second is the anonymous aci's being readable. Kerchoff's principle states "knowledge of the system, should not compromise the system", but CVE hunting means people assign ridiculous issues to software. This is not a security issue or risk in any way shape or form.

There are some changes that have been made to the example aci's to "help" with this issue if people get CVE-paranoia. They are available in 1.4.0.22 and higher. I will be submitting an update soon for this. 

Thanks,
Comment 15 Swamp Workflow Management 2019-08-15 19:14:33 UTC
SUSE-SU-2019:2155-1: An update that solves 8 vulnerabilities and has two fixes is now available.

Category: security (important)
Bug References: 1083689,1092187,1099465,1105606,1108674,1109609,1120189,1132385,1144797,991201
CVE References: CVE-2016-5416,CVE-2018-1054,CVE-2018-10871,CVE-2018-1089,CVE-2018-10935,CVE-2018-14638,CVE-2018-14648,CVE-2019-3883
Sources used:
SUSE Linux Enterprise Module for Server Applications 15-SP1 (src):    389-ds-1.4.0.26~git0.8a2d3de6f-4.14.1
SUSE Linux Enterprise Module for Server Applications 15 (src):    389-ds-1.4.0.26~git0.8a2d3de6f-4.14.1
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 (src):    389-ds-1.4.0.26~git0.8a2d3de6f-4.14.1
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 (src):    389-ds-1.4.0.26~git0.8a2d3de6f-4.14.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 16 Marcus Meissner 2019-10-30 08:45:19 UTC
done
Comment 17 Swamp Workflow Management 2020-04-11 22:50:59 UTC
This is an autogenerated message for OBS integration:
This bug (991201) was mentioned in
https://build.opensuse.org/request/show/793266 15.1 / 389-ds