Oval Definition:oval:com.ubuntu.bionic:def:2019130570000000
Revision Date:2019-07-26Version:1
Title:CVE-2019-13057 on Ubuntu 18.04 LTS (bionic) - low.
Description:An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from another database during a SASL bind or with a proxyAuthz (RFC 4370) control. (It is not a common configuration to deploy a system where the server administrator and a DB administrator enjoy different levels of trust.)
Family:unixClass:vulnerability
Status:Reference(s):CVE-2019-13057
Platform(s):Ubuntu 18.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 18.04 LTS (bionic) is installed.
  • AND openldap package in bionic was vulnerable but has been fixed (note: '2.4.45+dfsg-1ubuntu1.3').
  • BACK