Sploitus

CVE-2014-0132

1 known exploit for CVE-2014-0132

The SASL authentication functionality in 389 Directory Server before 1.2.11.26 allows remote authenticated users to connect as an arbitrary user and gain privileges via the authzid parameter in a SASL/GSSAPI bind.

Affected products
389-Ds-Base, Centos, Red Hat
Fedoraproject 389 Directory Server
≤ 1.2.11.25, 1.2.11.1, 1.2.11.5, 1.2.11.6, 1.2.11.8, 1.2.11.9, 1.2.11.10, 1.2.11.11, 1.2.11.12, 1.2.11.13, 1.2.11.14, 1.2.11.15, 1.2.11.17, 1.2.11.19, 1.2.11.20, 1.2.11.21, 1.2.11.22, 1.2.11.23
Fix
Available
CVSS 2.0
6.5 MEDIUM
EPSS
2.2% (81th percentile)
Weakness
CWE-287
NVD status
Modified
Published
2014-03-18
CVE-2014-0132 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2014-0132

Proof-of-concept code and exploit modules indexed by Sploitus