4.3

CVE-2007-5794

Race condition in nss_ldap, when used in applications that are linked against the pthread library and fork after a call to nss_ldap, might send user data to the wrong process because of improper handling of the LDAP connection. NOTE: this issue was originally reported for Dovecot with the wrong mailboxes being returned, but other applications might also be affected.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.16% 0.632
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00003.html
http://secunia.com/advisories/28838
Vendor Advisory
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=453868
http://bugs.gentoo.org/show_bug.cgi?id=198390
http://secunia.com/advisories/27670
Vendor Advisory
http://secunia.com/advisories/27768
Vendor Advisory
http://secunia.com/advisories/27839
Vendor Advisory
http://secunia.com/advisories/28061
Vendor Advisory
http://secunia.com/advisories/29083
Vendor Advisory
http://secunia.com/advisories/30352
Vendor Advisory
http://secunia.com/advisories/31227
Vendor Advisory
http://secunia.com/advisories/31524
Vendor Advisory
http://security.gentoo.org/glsa/glsa-200711-33.xml
http://support.avaya.com/elmodocs2/security/ASA-2008-332.htm
http://wiki.rpath.com/wiki/Advisories:rPSA-2007-0255
http://www.debian.org/security/2007/dsa-1430
http://www.dovecot.org/list/dovecot/2005-April/006859.html
http://www.dovecot.org/list/dovecot/2005-March/006345.html
http://www.mandriva.com/security/advisories?name=MDVSA-2008:049
http://www.redhat.com/support/errata/RHSA-2008-0389.html
http://www.redhat.com/support/errata/RHSA-2008-0715.html
http://www.securityfocus.com/archive/1/487985/100/0/threaded
http://www.securityfocus.com/bid/26452
Patch
http://www.securitytracker.com/id?1020088
https://bugzilla.redhat.com/show_bug.cgi?id=154314
https://bugzilla.redhat.com/show_bug.cgi?id=367461
https://exchange.xforce.ibmcloud.com/vulnerabilities/38505
https://issues.rpath.com/browse/RPL-1913
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10625