UBUNTU-CVE-2021-3652

Source
https://ubuntu.com/security/CVE-2021-3652
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-3652.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2021-3652
Related
Published
2022-04-18T17:15:00Z
Modified
2022-04-18T17:15:00Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

A flaw was found in 389-ds-base. If an asterisk is imported as password hashes, either accidentally or maliciously, then instead of being inactive, any password will successfully match during authentication. This flaw allows an attacker to successfully authenticate as a user whose password was disabled.

References

Affected packages

Ubuntu:18.04:LTS / 389-ds-base

Package

Name
389-ds-base
Purl
pkg:deb/ubuntu/389-ds-base?arch=src?distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.3.7.10-1ubuntu1

Affected versions

1.*

1.3.7.5-1
1.3.7.5-1build1
1.3.7.5-1build2
1.3.7.9-1
1.3.7.10-1

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "low",
    "binaries": [
        {
            "binary_version": "1.3.7.10-1ubuntu1",
            "binary_name": "389-ds"
        },
        {
            "binary_version": "1.3.7.10-1ubuntu1",
            "binary_name": "389-ds-base"
        },
        {
            "binary_version": "1.3.7.10-1ubuntu1",
            "binary_name": "389-ds-base-dbgsym"
        },
        {
            "binary_version": "1.3.7.10-1ubuntu1",
            "binary_name": "389-ds-base-dev"
        },
        {
            "binary_version": "1.3.7.10-1ubuntu1",
            "binary_name": "389-ds-base-libs"
        },
        {
            "binary_version": "1.3.7.10-1ubuntu1",
            "binary_name": "389-ds-base-libs-dbgsym"
        },
        {
            "binary_version": "1.3.7.10-1ubuntu1",
            "binary_name": "python3-dirsrvtests"
        },
        {
            "binary_version": "1.3.7.10-1ubuntu1",
            "binary_name": "python3-lib389"
        }
    ]
}