Lucene search

K
cveRedhatCVE-2007-5794
HistoryNov 13, 2007 - 11:46 p.m.

CVE-2007-5794

2007-11-1323:46:00
CWE-362
redhat
web.nvd.nist.gov
34
cve-2007-5794
nss_ldap
pthread library
race condition
ldap connection
security vulnerability

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

AI Score

6

Confidence

Low

EPSS

0.013

Percentile

86.2%

Race condition in nss_ldap, when used in applications that are linked against the pthread library and fork after a call to nss_ldap, might send user data to the wrong process because of improper handling of the LDAP connection. NOTE: this issue was originally reported for Dovecot with the wrong mailboxes being returned, but other applications might also be affected.

Affected configurations

Nvd
Node
nss_ldapnss_ldap
VendorProductVersionCPE
nss_ldapnss_ldap*cpe:2.3:a:nss_ldap:nss_ldap:*:*:*:*:*:*:*:*

References

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

AI Score

6

Confidence

Low

EPSS

0.013

Percentile

86.2%