National Vulnerability Database

National Vulnerability Database

National Vulnerability
Database

CVE-2007-5794 Detail

Current Description

Race condition in nss_ldap, when used in applications that are linked against the pthread library and fork after a call to nss_ldap, might send user data to the wrong process because of improper handling of the LDAP connection. NOTE: this issue was originally reported for Dovecot with the wrong mailboxes being returned, but other applications might also be affected.

Source:  MITRE
View Analysis Description

Impact

CVSS v2.0 Severity and Metrics:

Base Score: 4.3 MEDIUM
Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N) (V2 legend)
Impact Subscore: 2.9
Exploitability Subscore: 8.6


Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (AU): None
Confidentiality (C): Partial
Integrity (I): None
Availability (A): None
Additional Information:
Allows unauthorized disclosure of information

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to nvd@nist.gov.

Hyperlink Resource
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=453868
http://bugs.gentoo.org/show_bug.cgi?id=198390
http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00003.html
http://security.gentoo.org/glsa/glsa-200711-33.xml
http://support.avaya.com/elmodocs2/security/ASA-2008-332.htm
http://wiki.rpath.com/wiki/Advisories:rPSA-2007-0255
http://www.debian.org/security/2007/dsa-1430
http://www.dovecot.org/list/dovecot/2005-April/006859.html
http://www.dovecot.org/list/dovecot/2005-March/006345.html
http://www.mandriva.com/security/advisories?name=MDVSA-2008:049
http://www.redhat.com/support/errata/RHSA-2008-0389.html
http://www.redhat.com/support/errata/RHSA-2008-0715.html
http://www.securityfocus.com/archive/1/487985/100/0/threaded
http://www.securityfocus.com/bid/26452 Patch
http://www.securitytracker.com/id?1020088
https://bugzilla.redhat.com/show_bug.cgi?id=154314
https://bugzilla.redhat.com/show_bug.cgi?id=367461
https://exchange.xforce.ibmcloud.com/vulnerabilities/38505
https://issues.rpath.com/browse/RPL-1913
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10625

Technical Details

Vulnerability Type (View All)

  • Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') (CWE-362)

Known Affected Software Configurations Switch to CPE 2.2

Configuration 1 ( hide )
 cpe:2.3:a:nss_ldap:nss_ldap:*:*:*:*:*:*:*:*
     Show Matching CPE(s)


Change History

4 change records found - show changes

Quick Info

CVE Dictionary Entry:
CVE-2007-5794
NVD Published Date:
11/13/2007
NVD Last Modified:
10/15/2018