• 公告ID (KylinSec-SA-2022-1195)

摘要:

A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When executed in verbose mode, the dscreate and dsconf commands may display sensitive information, such as the Directory Manager password. An attacker, able to see the screen or record the terminal standard error output, could use this flaw to gain sensitive information.

安全等级: Low

公告ID: KylinSec-SA-2022-1195

发布日期: 2022年11月18日

关联CVE: CVE-2019-10224  

  • 详细介绍

1. 漏洞描述

   

A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When executed in verbose mode, the dscreate and dsconf commands may display sensitive information, such as the Directory Manager password. An attacker, able to see the screen or record the terminal standard error output, could use this flaw to gain sensitive information.

2. 影响范围

cve名称 产品 组件 是否受影响
CVE-2019-10224 KY3.4-4A three-eight-nine-ds-base Unaffected
CVE-2019-10224 KY3.4-5 three-eight-nine-ds-base Unaffected
CVE-2019-10224 KY3.5.1 three-eight-nine-ds-base Unaffected

3. 影响组件

    无

4. 修复版本

    无

5. 修复方法

   无

6. 下载链接

    无
上一篇:KylinSec-SA-2022-1194 下一篇:KylinSec-SA-2022-1196