1.2

CVE-2012-2678

389 Directory Server before 1.2.11.6 (aka Red Hat Directory Server before 8.2.10-3), after the password for a LDAP user has been changed and before the server has been reset, allows remote attackers to read the plaintext password via the unhashed#user#password attribute.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Directory Server Version <= 8.2
Redhat ≫ Directory Server Version 7.1
Redhat ≫ Directory Server Version 8.0
Redhat ≫ Directory Server Version 8.1
Fedoraproject ≫ 389 Directory Server Version <= 1.2.11.5
Fedoraproject ≫ 389 Directory Server Version 1.2.5 Update rc1
Fedoraproject ≫ 389 Directory Server Version 1.2.5 Update rc2
Fedoraproject ≫ 389 Directory Server Version 1.2.5 Update rc3
Fedoraproject ≫ 389 Directory Server Version 1.2.5 Update rc4
Fedoraproject ≫ 389 Directory Server Version 1.2.6 Update a2
Fedoraproject ≫ 389 Directory Server Version 1.2.6 Update a3
Fedoraproject ≫ 389 Directory Server Version 1.2.6 Update a4
Fedoraproject ≫ 389 Directory Server Version 1.2.6 Update rc1
Fedoraproject ≫ 389 Directory Server Version 1.2.6 Update rc2
Fedoraproject ≫ 389 Directory Server Version 1.2.6 Update rc3
Fedoraproject ≫ 389 Directory Server Version 1.2.6 Update rc6
Fedoraproject ≫ 389 Directory Server Version 1.2.6 Update rc7
Fedoraproject ≫ 389 Directory Server Version 1.2.6.1
Fedoraproject ≫ 389 Directory Server Version 1.2.7 Update alpha3
Fedoraproject ≫ 389 Directory Server Version 1.2.7.5
Fedoraproject ≫ 389 Directory Server Version 1.2.8 Update alpha1
Fedoraproject ≫ 389 Directory Server Version 1.2.8 Update alpha2
Fedoraproject ≫ 389 Directory Server Version 1.2.8 Update alpha3
Fedoraproject ≫ 389 Directory Server Version 1.2.8 Update rc1
Fedoraproject ≫ 389 Directory Server Version 1.2.8 Update rc2
Fedoraproject ≫ 389 Directory Server Version 1.2.8.1
Fedoraproject ≫ 389 Directory Server Version 1.2.8.2
Fedoraproject ≫ 389 Directory Server Version 1.2.8.3
Fedoraproject ≫ 389 Directory Server Version 1.2.9.9
Fedoraproject ≫ 389 Directory Server Version 1.2.10 Update alpha8
Fedoraproject ≫ 389 Directory Server Version 1.2.10 Update rc1
Fedoraproject ≫ 389 Directory Server Version 1.2.10.1
Fedoraproject ≫ 389 Directory Server Version 1.2.10.2
Fedoraproject ≫ 389 Directory Server Version 1.2.10.3
Fedoraproject ≫ 389 Directory Server Version 1.2.10.4
Fedoraproject ≫ 389 Directory Server Version 1.2.10.7
Fedoraproject ≫ 389 Directory Server Version 1.2.11.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.64% 0.456
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 1.2 1.9 2.9
AV:L/AC:H/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://directory.fedoraproject.org/wiki/Release_Notes
http://osvdb.org/83336
http://rhn.redhat.com/errata/RHSA-2012-0997.html
Vendor Advisory
http://rhn.redhat.com/errata/RHSA-2012-1041.html
Vendor Advisory
http://secunia.com/advisories/49734
Vendor Advisory
http://www.securityfocus.com/bid/54153
https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03772083
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19353