CVE-2014-0132
389-ds: flaw in parsing authzid can lead to privilege escalation
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The SASL authentication functionality in 389 Directory Server before 1.2.11.26 allows remote authenticated users to connect as an arbitrary user and gain privileges via the authzid parameter in a SASL/GSSAPI bind.
La funcionalidad de autenticación SASL en 389 Directory Server anterior a 1.2.11.26 permite a usuarios remotos autenticados conectar como un usuario arbitrario y ganar privilegios a través del parámetro authzid en un SASL/GSSAPI bind.
The 389 Directory Server is an LDAPv3 compliant server. The base packages include the Lightweight Directory Access Protocol server and command-line utilities for server administration. It was discovered that the 389 Directory Server did not properly handle certain SASL-based authentication mechanisms. A user able to authenticate to the directory using these SASL mechanisms could connect as any other directory user, including the administrative Directory Manager account. This could allow them to modify configuration values, as well as read and write any data the directory holds.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2013-12-03 CVE Reserved
- 2014-03-14 CVE Published
- 2024-08-06 CVE Updated
- 2024-08-06 First Exploit
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-287: Improper Authentication
- CWE-290: Authentication Bypass by Spoofing
CAPEC
References (7)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://fedorahosted.org/389/changeset/76acff12a86110d4165f94e2cba13ef5c7ebc38a | 2024-08-06 |
URL | Date | SRC |
---|---|---|
https://fedorahosted.org/389/ticket/47739 | 2023-02-13 |
URL | Date | SRC |
---|---|---|
http://rhn.redhat.com/errata/RHSA-2014-0292.html | 2023-02-13 | |
http://secunia.com/advisories/57412 | 2023-02-13 | |
http://secunia.com/advisories/57427 | 2023-02-13 | |
https://access.redhat.com/security/cve/CVE-2014-0132 | 2014-03-13 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1074845 | 2014-03-13 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | <= 1.2.11.25 Search vendor "Fedoraproject" for product "389 Directory Server" and version " <= 1.2.11.25" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.11.1 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.11.1" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.11.5 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.11.5" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.11.6 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.11.6" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.11.8 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.11.8" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.11.9 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.11.9" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.11.10 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.11.10" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.11.11 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.11.11" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.11.12 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.11.12" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.11.13 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.11.13" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.11.14 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.11.14" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.11.15 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.11.15" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.11.17 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.11.17" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.11.19 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.11.19" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.11.20 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.11.20" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.11.21 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.11.21" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.11.22 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.11.22" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | 389 Directory Server Search vendor "Fedoraproject" for product "389 Directory Server" | 1.2.11.23 Search vendor "Fedoraproject" for product "389 Directory Server" and version "1.2.11.23" | - |
Affected
|