UBUNTU-CVE-2012-2746

Source
https://ubuntu.com/security/CVE-2012-2746
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2012/UBUNTU-CVE-2012-2746.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2012-2746
Upstream
  • CVE-2012-2746
Withdrawn
2025-07-18T16:42:46Z
Published
2012-07-03T16:40:00Z
Modified
2025-07-16T08:10:34.360941Z
Severity
  • Ubuntu - medium
Summary
[none]
Details

389 Directory Server before 1.2.11.6 (aka Red Hat Directory Server before 8.2.10-3), when the password of a LDAP user has been changed and audit logging is enabled, saves the new password to the log in plain text, which allows remote authenticated users to read the password.

References

Affected packages

Ubuntu:14.04:LTS / 389-ds-base

Package

Name
389-ds-base
Purl
pkg:deb/ubuntu/389-ds-base@1.3.2.16-0ubuntu1?arch=source&distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.3.2.16-0ubuntu1

Affected versions

1.*
1.3.1.9-0ubuntu2
1.3.1.9-0ubuntu3
1.3.1.9-0ubuntu4
1.3.2.11-0ubuntu1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "1.3.2.16-0ubuntu1",
            "binary_name": "389-ds"
        },
        {
            "binary_version": "1.3.2.16-0ubuntu1",
            "binary_name": "389-ds-base"
        },
        {
            "binary_version": "1.3.2.16-0ubuntu1",
            "binary_name": "389-ds-base-dbg"
        },
        {
            "binary_version": "1.3.2.16-0ubuntu1",
            "binary_name": "389-ds-base-dev"
        },
        {
            "binary_version": "1.3.2.16-0ubuntu1",
            "binary_name": "389-ds-base-libs"
        },
        {
            "binary_version": "1.3.2.16-0ubuntu1",
            "binary_name": "389-ds-base-libs-dbg"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2012/UBUNTU-CVE-2012-2746.json"