CVE-2012-0833

low
Published 2012-07-03 Β· Modified 2026-04-29
CVSS v3
β€”
CVSS v4 NEW
β€”
not yet in upstream
VIR risk
2.3

Description

The acllas__handle_group_entry function in servers/plugins/acl/acllas.c in 389 Directory Server before 1.2.10 does not properly handled access control instructions (ACIs) that use certificate groups, which allows remote authenticated LDAP users with a certificate group to cause a denial of service (infinite loop and CPU consumption) by binding to the server.

Predictions

Exploit likelihood
20%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker Β· View original β†— Β· DFSG

CVE-2012-0833 NameCVE-2012-0833 DescriptionThe acllas__handle_group_entry function in servers/plugins/acl/acllas.c in 389 Directory Server before 1.2.10 does not properly handled access control instructions (ACIs) that use certificate groups, which allows remote authenticated LDAP users with a certificate group to cause a denial of service (infinite loop and CPU consumption) by binding to the…

CVE-2012-0833

NameCVE-2012-0833
DescriptionThe acllas__handle_group_entry function in servers/plugins/acl/acllas.c in 389 Directory Server before 1.2.10 does not properly handled access control instructions (ACIs) that use certificate groups, which allows remote authenticated LDAP users with a certificate group to cause a denial of service (infinite loop and CPU consumption) by binding to the server.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
389-ds-base (PTS)bullseye1.4.4.11-2fixed
bullseye (security)1.4.4.11-2+deb11u1fixed
bookworm2.3.1+dfsg1-1+deb12u1fixed
trixie3.1.2+dfsg1-1+deb13u1fixed
sid3.1.2+vendor1-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
389-ds-basesource(unstable)(not affected)

Notes

- 389-ds-base <not-affected> (Fixed before initial upload)

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
- 389-ds-base <not-affected> (Fixed before initial upload)

OS impact

debian Debian Fixed 4 releases
VersionStatusFixed in
trixie Fixed 0
sid Fixed 0
bullseye Fixed 0
bookworm Fixed 0

Application impact

VendorProductVersionsFixed
fedora fedoraproject389_directory_server{"endIncluding":"1.2.10"}
fedora fedoraproject389_directory_server1.2.1
fedora fedoraproject389_directory_server1.2.2
fedora fedoraproject389_directory_server1.2.3
fedora fedoraproject389_directory_server1.2.5
fedora fedoraproject389_directory_server1.2.6
fedora fedoraproject389_directory_server1.2.6.1
fedora fedoraproject389_directory_server1.2.7
fedora fedoraproject389_directory_server1.2.7.5
fedora fedoraproject389_directory_server1.2.8
fedora fedoraproject389_directory_server1.2.8.1
fedora fedoraproject389_directory_server1.2.8.2
fedora fedoraproject389_directory_server1.2.8.3
fedora fedoraproject389_directory_server1.2.9.9
fedora fedoraproject389_directory_server1.2.10

References

CWEs

CWE-264

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.