DEBIAN-CVE-2018-1337

Source
https://security-tracker.debian.org/tracker/CVE-2018-1337
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2018-1337.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2018-1337
Upstream
  • CVE-2018-1337
Published
2018-07-10T13:29:00.293Z
Modified
2026-06-01T09:00:06.531315980Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

In Apache Directory LDAP API before 1.0.2, a bug in the way the SSL Filter was setup made it possible for another thread to use the connection before the TLS layer has been established, if the connection has already been used and put back in a pool of connections, leading to leaking any information contained in this request (including the credentials when sending a BIND request).

References

Affected packages

Debian:11 / apache-directory-api

Package

Name
apache-directory-api
Purl
pkg:deb/debian/apache-directory-api?arch=source&distro=bullseye

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.0.0-2
2.*
2.1.2-1
2.1.2-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2018-1337.json"

Debian:12 / apache-directory-api

Package

Name
apache-directory-api
Purl
pkg:deb/debian/apache-directory-api?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.1.2-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2018-1337.json"

Debian:13 / apache-directory-api

Package

Name
apache-directory-api
Purl
pkg:deb/debian/apache-directory-api?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.1.2-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2018-1337.json"

Debian:14 / apache-directory-api

Package

Name
apache-directory-api
Purl
pkg:deb/debian/apache-directory-api?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.1.2-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2018-1337.json"