RedHat: RHSA-2019-3401:01 Important: 389-ds:1.4 security, bug fix,
Summary
389 Directory Server is an LDAP version 3 (LDAPv3) compliant server. The
base packages include the Lightweight Directory Access Protocol (LDAP)
server and command-line utilities for server administration.
The following packages have been upgraded to a later upstream version:
389-ds-base (1.4.1.3). (BZ#1712467)
Security Fix(es):
* 389-ds-base: Read permission check bypass via the deref plugin
(CVE-2019-14824)
* 389-ds-base: replication and the Retro Changelog plugin store plaintext
password by default (CVE-2018-10871)
* 389-ds-base: DoS via hanging secured connections (CVE-2019-3883)
* 389-ds-base: using dscreate in verbose mode results in information
disclosure (CVE-2019-10224)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the Red Hat
Enterprise Linux 8.1 Release Notes linked from the References section.
Summary
Solution
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
References
https://access.redhat.com/security/cve/CVE-2018-10871 https://access.redhat.com/security/cve/CVE-2019-3883 https://access.redhat.com/security/cve/CVE-2019-10224 https://access.redhat.com/security/cve/CVE-2019-14824 https://access.redhat.com/security/updates/classification/#important https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.1_release_notes/
Package List
Red Hat Enterprise Linux AppStream (v. 8):
Source:
389-ds-base-1.4.1.3-7.module+el8.1.0+4150+5b8c2c1f.src.rpm
aarch64:
389-ds-base-1.4.1.3-7.module+el8.1.0+4150+5b8c2c1f.aarch64.rpm
389-ds-base-debuginfo-1.4.1.3-7.module+el8.1.0+4150+5b8c2c1f.aarch64.rpm
389-ds-base-debugsource-1.4.1.3-7.module+el8.1.0+4150+5b8c2c1f.aarch64.rpm
389-ds-base-devel-1.4.1.3-7.module+el8.1.0+4150+5b8c2c1f.aarch64.rpm
389-ds-base-legacy-tools-1.4.1.3-7.module+el8.1.0+4150+5b8c2c1f.aarch64.rpm
389-ds-base-legacy-tools-debuginfo-1.4.1.3-7.module+el8.1.0+4150+5b8c2c1f.aarch64.rpm
389-ds-base-libs-1.4.1.3-7.module+el8.1.0+4150+5b8c2c1f.aarch64.rpm
389-ds-base-libs-debuginfo-1.4.1.3-7.module+el8.1.0+4150+5b8c2c1f.aarch64.rpm
389-ds-base-snmp-1.4.1.3-7.module+el8.1.0+4150+5b8c2c1f.aarch64.rpm
389-ds-base-snmp-debuginfo-1.4.1.3-7.module+el8.1.0+4150+5b8c2c1f.aarch64.rpm
noarch:
python3-lib389-1.4.1.3-7.module+el8.1.0+4150+5b8c2c1f.noarch.rpm
ppc64le:
389-ds-base-1.4.1.3-7.module+el8.1.0+4150+5b8c2c1f.ppc64le.rpm
389-ds-base-debuginfo-1.4.1.3-7.module+el8.1.0+4150+5b8c2c1f.ppc64le.rpm
389-ds-base-debugsource-1.4.1.3-7.module+el8.1.0+4150+5b8c2c1f.ppc64le.rpm
389-ds-base-devel-1.4.1.3-7.module+el8.1.0+4150+5b8c2c1f.ppc64le.rpm
389-ds-base-legacy-tools-1.4.1.3-7.module+el8.1.0+4150+5b8c2c1f.ppc64le.rpm
389-ds-base-legacy-tools-debuginfo-1.4.1.3-7.module+el8.1.0+4150+5b8c2c1f.ppc64le.rpm
389-ds-base-libs-1.4.1.3-7.module+el8.1.0+4150+5b8c2c1f.ppc64le.rpm
389-ds-base-libs-debuginfo-1.4.1.3-7.module+el8.1.0+4150+5b8c2c1f.ppc64le.rpm
389-ds-base-snmp-1.4.1.3-7.module+el8.1.0+4150+5b8c2c1f.ppc64le.rpm
389-ds-base-snmp-debuginfo-1.4.1.3-7.module+el8.1.0+4150+5b8c2c1f.ppc64le.rpm
s390x:
389-ds-base-1.4.1.3-7.module+el8.1.0+4150+5b8c2c1f.s390x.rpm
389-ds-base-debuginfo-1.4.1.3-7.module+el8.1.0+4150+5b8c2c1f.s390x.rpm
389-ds-base-debugsource-1.4.1.3-7.module+el8.1.0+4150+5b8c2c1f.s390x.rpm
389-ds-base-devel-1.4.1.3-7.module+el8.1.0+4150+5b8c2c1f.s390x.rpm
389-ds-base-legacy-tools-1.4.1.3-7.module+el8.1.0+4150+5b8c2c1f.s390x.rpm
389-ds-base-legacy-tools-debuginfo-1.4.1.3-7.module+el8.1.0+4150+5b8c2c1f.s390x.rpm
389-ds-base-libs-1.4.1.3-7.module+el8.1.0+4150+5b8c2c1f.s390x.rpm
389-ds-base-libs-debuginfo-1.4.1.3-7.module+el8.1.0+4150+5b8c2c1f.s390x.rpm
389-ds-base-snmp-1.4.1.3-7.module+el8.1.0+4150+5b8c2c1f.s390x.rpm
389-ds-base-snmp-debuginfo-1.4.1.3-7.module+el8.1.0+4150+5b8c2c1f.s390x.rpm
x86_64:
389-ds-base-1.4.1.3-7.module+el8.1.0+4150+5b8c2c1f.x86_64.rpm
389-ds-base-debuginfo-1.4.1.3-7.module+el8.1.0+4150+5b8c2c1f.x86_64.rpm
389-ds-base-debugsource-1.4.1.3-7.module+el8.1.0+4150+5b8c2c1f.x86_64.rpm
389-ds-base-devel-1.4.1.3-7.module+el8.1.0+4150+5b8c2c1f.x86_64.rpm
389-ds-base-legacy-tools-1.4.1.3-7.module+el8.1.0+4150+5b8c2c1f.x86_64.rpm
389-ds-base-legacy-tools-debuginfo-1.4.1.3-7.module+el8.1.0+4150+5b8c2c1f.x86_64.rpm
389-ds-base-libs-1.4.1.3-7.module+el8.1.0+4150+5b8c2c1f.x86_64.rpm
389-ds-base-libs-debuginfo-1.4.1.3-7.module+el8.1.0+4150+5b8c2c1f.x86_64.rpm
389-ds-base-snmp-1.4.1.3-7.module+el8.1.0+4150+5b8c2c1f.x86_64.rpm
389-ds-base-snmp-debuginfo-1.4.1.3-7.module+el8.1.0+4150+5b8c2c1f.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/
Topic
An update for the 389-ds:1.4 module is now available for Red Hat Enterprise
Linux 8.
Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.
Topic
Relevant Releases Architectures
Red Hat Enterprise Linux AppStream (v. 8) - aarch64, noarch, ppc64le, s390x, x86_64
Bugs Fixed
1591480 - CVE-2018-10871 389-ds-base: replication and the Retro Changelog plugin store plaintext password by default
1654056 - /usr/lib/systemd/system/dirsrv@.service:40: .include directives are deprecated
1654059 - CVE-2019-10224 389-ds-base: using dscreate in verbose mode results in information disclosure [rhel-8]
1677147 - CVE-2019-10224 389-ds-base: using dscreate in verbose mode results in information disclosure
1678517 - ipa role-mod DatabaseError changing cn
1693612 - CVE-2019-3883 389-ds-base: DoS via hanging secured connections
1702024 - Cannot create Directory Server's instances using dscreate
1706224 - Protocol setting is inconsistent in FIPS mode
1712467 - Rebase 389-ds-base on RHEL 8.1
1715675 - Fix potential ipv6 issues
1717540 - Address covscan warnings
1720331 - Log the actual base DN when the search fails with "invalid attribute request".
1725815 - consistency in the replication error codes while setting nsds5replicaid=65535
1729069 - IPA upgrade fails for latest ipa package when setup in multi master mode
1739183 - CleanAllRUV task limit not enforced
1747448 - CVE-2019-14824 389-ds-base: Read permission check bypass via the deref plugin