CVE-2012-0833
The acllas__handle_group_entry function in servers/plugins/acl/acllas.c in 389 Directory Server before 1.2.10 does not properly handled access control instructions (ACIs) that use certificate groups, which allows remote authenticated LDAP users with a certificate group to cause a denial of service (infinite loop and CPU consumption) by binding to the server.
- Affected products
- 389 Directory Server, Centos, Red Hat
- Fedoraproject 389 Directory Server
- ≤ 1.2.10, 1.2.1, 1.2.2, 1.2.3, 1.2.5, 1.2.6, 1.2.6.1, 1.2.7, 1.2.7.5, 1.2.8, 1.2.8.1, 1.2.8.2, 1.2.8.3, 1.2.9.9
- Fix
- Available
- CVSS 2.0
- 2.3 LOW
- EPSS
- 0.9% (57th percentile)
- Weakness
- CWE-264
- NVD status
- Modified
- Published
- 2012-07-03
CVE-2012-0833 at NVD
No indexed exploits for CVE-2012-0833 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2012-0833 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.