Moderate: redhat-ds:11 security and bug fix update

Related Vulnerabilities: CVE-2020-35518   CVE-2020-35518   CVE-2020-35518   CVE-2020-35518  

Synopsis

Moderate: redhat-ds:11 security and bug fix update

Type/Severity

Security Advisory: Moderate

Topic

An update for the redhat-ds:11 module is now available for Red Hat Directory Server 11.1 for RHEL 8.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat Directory Server is an LDAPv3-compliant directory server. The suite of packages includes the Lightweight Directory Access Protocol (LDAP) server and command-line utilities for server administration, the Administration Server HTTP agent package, and the GUI console packages.

Security Fix(es):

  • 389-ds-base: information disclosure during the binding of a DN (CVE-2020-35518)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Bug Fix(es):

  • RHDS11: “write” permission of ACI changes ns-slapd’s behavior on search operation (BZ#1909675)

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Directory Server 11 x86_64

Fixes

  • BZ - 1905565 - CVE-2020-35518 389-ds-base: information disclosure during the binding of a DN
  • BZ - 1909675 - RHDS11: “write” permission of ACI changes ns-slapd’s behavior on search operation
  • BZ - 1923217 - CVE-2020-35518 RHDS: information disclosure during the binding of a DN

CVEs

References