389-ds-base is an LDAPv3 compliant server which includes the LDAP server and command line utilities for server administration.
Security Fix(es):
When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be used by an unauthenticated attacker to check the existence of an entry in the LDAP database.(CVE-2020-35518)
{ "severity": "Medium" }
{ "aarch64": [ "389-ds-base-debugsource-1.4.3.20-1.oe2203.aarch64.rpm", "389-ds-base-devel-1.4.3.20-1.oe2203.aarch64.rpm", "389-ds-base-debuginfo-1.4.3.20-1.oe2203.aarch64.rpm", "389-ds-base-1.4.3.20-1.oe2203.aarch64.rpm", "389-ds-base-legacy-tools-1.4.3.20-1.oe2203.aarch64.rpm", "389-ds-base-snmp-1.4.3.20-1.oe2203.aarch64.rpm", "389-ds-base-help-1.4.3.20-1.oe2203.aarch64.rpm" ], "src": [ "389-ds-base-1.4.3.20-1.oe2203.src.rpm" ], "x86_64": [ "389-ds-base-debuginfo-1.4.3.20-1.oe2203.x86_64.rpm", "389-ds-base-devel-1.4.3.20-1.oe2203.x86_64.rpm", "389-ds-base-1.4.3.20-1.oe2203.x86_64.rpm", "389-ds-base-help-1.4.3.20-1.oe2203.x86_64.rpm", "389-ds-base-legacy-tools-1.4.3.20-1.oe2203.x86_64.rpm", "389-ds-base-debugsource-1.4.3.20-1.oe2203.x86_64.rpm", "389-ds-base-snmp-1.4.3.20-1.oe2203.x86_64.rpm" ], "noarch": [ "cockpit-389-ds-1.4.3.20-1.oe2203.noarch.rpm", "python3-lib389-1.4.3.20-1.oe2203.noarch.rpm" ] }