« Volver al listado

CVE-2012-0833

Estado: ModificadaBaja (2.3)—

The acllas__handle_group_entry function in servers/plugins/acl/acllas.c in 389 Directory Server before 1.2.10 does not properly handled access control instructions (ACIs) that use certificate groups, which allows remote authenticated LDAP users with a certificate group to cause a denial of service (infinite loop and CPU consumption) by binding to the server.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2012-0833",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 2.3,
          "accessVector": "ADJACENT_NETWORK",
          "vectorString": "AV:A/AC:M/Au:S/C:N/I:N/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "NONE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 4.4,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2012-07-03T16:40:31.583",
  "references": [
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2012-0813.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://secunia.com/advisories/48035",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://secunia.com/advisories/49562",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://fedorahosted.org/389/changeset/1bbbb3e5049c1aa0650546efab87ed2f1ea59637/389-ds-base",
      "tags": [
        "Exploit",
        "Patch"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://fedorahosted.org/389/ticket/162",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2012-0813.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/48035",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/49562",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://fedorahosted.org/389/changeset/1bbbb3e5049c1aa0650546efab87ed2f1ea59637/389-ds-base",
      "tags": [
        "Exploit",
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://fedorahosted.org/389/ticket/162",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The acllas__handle_group_entry function in servers/plugins/acl/acllas.c in 389 Directory Server before 1.2.10 does not properly handled access control instructions (ACIs) that use certificate groups, which allows remote authenticated LDAP users with a certificate group to cause a denial of service (infinite loop and CPU consumption) by binding to the server."
    },
    {
      "lang": "es",
      "value": "La funcion acllas__handle_group_entry en servers/plugins/acl/acllas.c en 389 Directory Server anterior a v1.2.10 no  maneja adecuadamente las instrucciones de control de acceso (ACIs) que utilizan los grupos de certificados, permitiendo a los usuarios autenticados de LDAP con un certificado de grupo causar una denegación de servicio (bucle infinito y consumo de CPU) mediante la unión (\"binding\") con el servidor."
    }
  ],
  "lastModified": "2026-06-16T23:38:21.010",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:*:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "35D900B4-B84B-49A3-8EDE-96D1900635C7",
              "versionEndIncluding": "1.2.10"
            },
            {
              "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CE2E9C8D-FFEE-424C-BBA6-42BD4309D18A"
            },
            {
              "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8F2E9CEF-F30D-4374-A7E2-052102B602A7"
            },
            {
              "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "16A8729B-B00B-4871-B083-6B10A5034721"
            },
            {
              "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6335FA65-9498-40AF-AE2B-034DA2823821"
            },
            {
              "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.5:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8CF92ADB-B5B0-43D7-93D8-CBA3AE46EB8D"
            },
            {
              "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.5:rc2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "17F8ED59-E27A-4B9B-8BB8-66FAB2B2DCFB"
            },
            {
              "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.5:rc3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4200CEAB-4E14-48C8-9D6F-F86796475019"
            },
            {
              "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.5:rc4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3179916B-F98C-4D10-82AB-59DCCACBE8DA"
            },
            {
              "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B44B5289-08BB-4D62-B60D-1BD738472B1D"
            },
            {
              "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.6:a2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "02392BBF-AFAB-4739-BAF6-E930692AB28F"
            },
            {
              "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.6:a3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BFF70436-E01E-4912-AC31-B600F5E8CB4F"
            },
            {
              "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.6:a4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "360BA51B-B47E-4537-B564-9E628DF4E6EA"
            },
            {
              "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.6:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "987F04BC-75DC-4959-AE32-070F11F9EBC2"
            },
            {
              "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.6:rc2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "078BCE55-90BB-48DE-92D1-9A152338158C"
            },
            {
              "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.6:rc3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "595F5AEE-E4A9-40E0-AF03-69AF689C4916"
            },
            {
              "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.6:rc6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FED47519-F254-4545-8551-FFBD0B4F9FAB"
            },
            {
              "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.6:rc7:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A06C0421-74B7-4F9D-9F3A-18BF62BDD4D9"
            },
            {
              "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.6.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "83F772DF-B8A7-4577-9AC6-3234B8C7FFAA"
            },
            {
              "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.7:alpha3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "60624BFB-BB50-47F9-BB6D-BC92B40988BF"
            },
            {
              "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.7.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "17C879AE-7435-43F5-94E5-A7ED84E46D0F"
            },
            {
              "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.8:alpha1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5809DC7B-AC50-4E03-A8FA-6C2C6B67A400"
            },
            {
              "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.8:alpha2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "04FED7B7-7D97-4020-9D5C-A7150B43838C"
            },
            {
              "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.8:alpha3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6CA6BAB0-4638-4341-8835-E24E58855C37"
            },
            {
              "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.8:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3C87A154-D750-4A93-B958-478CB17783F1"
            },
            {
              "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.8:rc2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "762AF16D-D7C3-4444-B8E5-88626D7DCE6A"
            },
            {
              "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.8.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2FF2BE2A-E90A-4336-864A-A76D9B1F0793"
            },
            {
              "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.8.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7EE57DD6-A59C-4073-8DBB-E8D667E9A206"
            },
            {
              "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.8.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5F65E0F9-731B-48E4-AF46-C8CAAE00820D"
            },
            {
              "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.9.9:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B8AD8024-EF26-46B3-80E1-25661A5C538A"
            },
            {
              "criteria": "cpe:2.3:a:fedoraproject:389_directory_server:1.2.10:alpha8:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A3DD52CC-C56A-4F62-BE61-BF826104B127"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}