PADL 'nss_ldap' Race Condition Security Vulnerability
BID:26452
Info
PADL 'nss_ldap' Race Condition Security Vulnerability
| Bugtraq ID: | 26452 |
| Class: | Race Condition Error |
| CVE: |
CVE-2007-5794 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 15 2007 12:00AM |
| Updated: | Aug 25 2008 11:15PM |
| Credit: | Josh Burley discovered this issue. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 8 SuSE SUSE Linux Enterprise Server 10 SP1 SuSE SUSE Linux Enterprise SDK 10 SP1 SuSE Suse Linux Enterprise Desktop 10 SP1 SuSE Linux Enterprise Server 9 SuSE Linux Enterprise Server 10.SP1 SuSE Linux Desktop 1.0 SuSE Linux 10.1 x86-64 SuSE Linux 10.1 x86 SuSE Linux 10.1 ppc SuSE Linux 10.0 x86-64 SuSE Linux 10.0 x86 SuSE Linux 10.0 ppc S.u.S.E. UnitedLinux 1.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. openSUSE 10.3 S.u.S.E. openSUSE 10.2 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Novell Linux POS 9 S.u.S.E. Novell Linux Desktop 9 rPath rPath Linux 1 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux AS 4 Redhat Enterprise Linux 5 server Redhat Desktop 4.0 Padl Software nss_ldap Build 258 Padl Software nss_ldap Build 220 Padl Software nss_ldap Build 211 Padl Software nss_ldap Build 202 Padl Software nss_ldap Build 199 Padl Software nss_ldap Build 198 Padl Software nss_ldap Build 194 Padl Software nss_ldap Build 192 Padl Software nss_ldap Build 191 Padl Software nss_ldap Build 190 Padl Software nss_ldap Build 189 Padl Software nss_ldap Build 188 Padl Software nss_ldap Build 187 Padl Software nss_ldap Build 186 Padl Software nss_ldap Build 185.3 Padl Software nss_ldap Build 185.2 Padl Software nss_ldap Build 185.1 Padl Software nss_ldap Build 185 Padl Software nss_ldap Build 184 Padl Software nss_ldap Build 183 Padl Software nss_ldap Build 181 Padl Software nss_ldap Build 180 Padl Software nss_ldap Build 173 Padl Software nss_ldap Build 172 Padl Software nss_ldap Build 122 Padl Software nss_ldap Build 121 Padl Software nss_ldap Build 113 Padl Software nss_ldap Build 107 Padl Software nss_ldap Build 105 Mandriva Linux Mandrake 2007.0 x86_64 Mandriva Linux Mandrake 2007.0 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 4.0 Gentoo Linux Foresight Linux Foresight Linux 1.1 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 Avaya Proactive Contact 4.0 Avaya Messaging Storage Server MSS 3.0 Avaya Message Networking MN 3.1 Avaya Communication Manager 4.0 Avaya Aura SIP Enablement Services 5.0 Avaya Aura Application Enablement Services 4.0.1 Avaya Aura Application Enablement Services 3.1.5 Avaya Aura Application Enablement Services 3.1.4 Avaya Aura Application Enablement Services 3.1.3 Avaya Aura Application Enablement Services 4.1 Avaya Aura Application Enablement Services 3.0 Avaya AES 4.2 Avaya AES 4.0 Avaya AES 3.1 |
| Not Vulnerable: |
Padl Software nss_ldap Build 259 |
Discussion
PADL 'nss_ldap' Race Condition Security Vulnerability
PADL 'nss_ldap' is prone to a race-condition security vulnerability; fixes are available.
An attacker may exploit this condition to obtain potentially sensitive data or to launch other attacks against an application that employs the vulnerable function.
The issue affects versions prior to PADL 'nss_ldap' Build 259.
PADL 'nss_ldap' is prone to a race-condition security vulnerability; fixes are available.
An attacker may exploit this condition to obtain potentially sensitive data or to launch other attacks against an application that employs the vulnerable function.
The issue affects versions prior to PADL 'nss_ldap' Build 259.
Exploit / POC
PADL 'nss_ldap' Race Condition Security Vulnerability
Specific exploit code is not likely required, but may help expose the race condition.
Specific exploit code is not likely required, but may help expose the race condition.
Solution / Fix
PADL 'nss_ldap' Race Condition Security Vulnerability
Solution:
The vendor has released updates to address this issue. Please see the references for more information.
Padl Software nss_ldap Build 185
Padl Software nss_ldap Build 187
Padl Software nss_ldap Build 190
Padl Software nss_ldap Build 198
Padl Software nss_ldap Build 189
Padl Software nss_ldap Build 180
Padl Software nss_ldap Build 181
Padl Software nss_ldap Build 122
Padl Software nss_ldap Build 185.3
Padl Software nss_ldap Build 258
Padl Software nss_ldap Build 113
Padl Software nss_ldap Build 186
Padl Software nss_ldap Build 194
Padl Software nss_ldap Build 220
Padl Software nss_ldap Build 173
Padl Software nss_ldap Build 211
Padl Software nss_ldap Build 121
Padl Software nss_ldap Build 185.2
Padl Software nss_ldap Build 105
Padl Software nss_ldap Build 202
Padl Software nss_ldap Build 184
Padl Software nss_ldap Build 107
Padl Software nss_ldap Build 199
Padl Software nss_ldap Build 185.1
Solution:
The vendor has released updates to address this issue. Please see the references for more information.
Padl Software nss_ldap Build 185
-
PADL Software nss_ldap.tgz
http://www.padl.com/download/nss_ldap.tgz
Padl Software nss_ldap Build 187
-
PADL Software nss_ldap.tgz
http://www.padl.com/download/nss_ldap.tgz
Padl Software nss_ldap Build 190
-
PADL Software nss_ldap.tgz
http://www.padl.com/download/nss_ldap.tgz
Padl Software nss_ldap Build 198
-
PADL Software nss_ldap.tgz
http://www.padl.com/download/nss_ldap.tgz
Padl Software nss_ldap Build 189
-
PADL Software nss_ldap.tgz
http://www.padl.com/download/nss_ldap.tgz
Padl Software nss_ldap Build 180
-
PADL Software nss_ldap.tgz
http://www.padl.com/download/nss_ldap.tgz
Padl Software nss_ldap Build 181
-
PADL Software nss_ldap.tgz
http://www.padl.com/download/nss_ldap.tgz
Padl Software nss_ldap Build 122
-
PADL Software nss_ldap.tgz
http://www.padl.com/download/nss_ldap.tgz
Padl Software nss_ldap Build 185.3
-
PADL Software nss_ldap.tgz
http://www.padl.com/download/nss_ldap.tgz
Padl Software nss_ldap Build 258
-
PADL Software nss_ldap.tgz
http://www.padl.com/download/nss_ldap.tgz
Padl Software nss_ldap Build 113
-
PADL Software nss_ldap.tgz
http://www.padl.com/download/nss_ldap.tgz
Padl Software nss_ldap Build 186
-
PADL Software nss_ldap.tgz
http://www.padl.com/download/nss_ldap.tgz
Padl Software nss_ldap Build 194
-
PADL Software nss_ldap.tgz
http://www.padl.com/download/nss_ldap.tgz
Padl Software nss_ldap Build 220
-
PADL Software nss_ldap.tgz
http://www.padl.com/download/nss_ldap.tgz
Padl Software nss_ldap Build 173
-
PADL Software nss_ldap.tgz
http://www.padl.com/download/nss_ldap.tgz
Padl Software nss_ldap Build 211
-
PADL Software nss_ldap.tgz
http://www.padl.com/download/nss_ldap.tgz
Padl Software nss_ldap Build 121
-
PADL Software nss_ldap.tgz
http://www.padl.com/download/nss_ldap.tgz
Padl Software nss_ldap Build 185.2
-
PADL Software nss_ldap.tgz
http://www.padl.com/download/nss_ldap.tgz
Padl Software nss_ldap Build 105
-
PADL Software nss_ldap.tgz
http://www.padl.com/download/nss_ldap.tgz
Padl Software nss_ldap Build 202
-
PADL Software nss_ldap.tgz
http://www.padl.com/download/nss_ldap.tgz
Padl Software nss_ldap Build 184
-
PADL Software nss_ldap.tgz
http://www.padl.com/download/nss_ldap.tgz
Padl Software nss_ldap Build 107
-
PADL Software nss_ldap.tgz
http://www.padl.com/download/nss_ldap.tgz
Padl Software nss_ldap Build 199
-
PADL Software nss_ldap.tgz
http://www.padl.com/download/nss_ldap.tgz
Padl Software nss_ldap Build 185.1
-
PADL Software nss_ldap.tgz
http://www.padl.com/download/nss_ldap.tgz
References
PADL 'nss_ldap' Race Condition Security Vulnerability
References:
References:
- Bugzilla Bug 154314: nss_ldap randomly replying with wrong user's data (Red Hat)
- Bugzilla Bug 367461: CVE-2007-5794 nss_ldap randomly replying with wrong user's (Red Hat)
- [Dovecot] Authentication and the wrong mailbox? (Rich West)
- [Dovecot] hanging imap... and users getting other users' emails! (Josh Burley)
- nss_ldap Homepage (Padl Software)
- ASA-2008-332 - nss_ldap security update (RHSA-2008-0715) (Avaya)
- RHSA-2008:0389-8 nss_ldap security and bug fix update (Red Hat)
- RHSA-2008:0715-5 nss_ldap security and bug fix update (Red Hat)