CVE-2012-2678
Publication date 3 July 2012
Last updated 24 July 2024
Ubuntu priority
Description
389 Directory Server before 1.2.11.6 (aka Red Hat Directory Server before 8.2.10-3), after the password for a LDAP user has been changed and before the server has been reset, allows remote attackers to read the plaintext password via the unhashed#user#password attribute.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| 389-ds-base | ||
| 16.04 LTS xenial |
Not affected
|
|
| 14.04 LTS trusty | Not in release | |