Bug 1007004 - (CVE-2016-5405) VUL-0: CVE-2016-5405: 389-ds: Password verification vulnerable to timing attack
(CVE-2016-5405)
VUL-0: CVE-2016-5405: 389-ds: Password verification vulnerable to timing attack
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other openSUSE 42.1
: P3 - Medium : Minor
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/174143/
CVSSv2:NVD:CVE-2016-5405:5.0:(AV:N/A...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2016-10-26 11:18 UTC by Andreas Stieger
Modified: 2018-12-03 02:36 UTC (History)
4 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Andreas Stieger 2016-10-26 11:18:20 UTC
via RH:

It was found that 389 Directory Server is vulnerable to a remote password disclosure via timing attack. Due to the use of strcmp and memcmp in the verification of passwords and hashes, remote attacker is able to tell the difference between computation times which makes him able to retrieve the password after many tries.

This affects systems storing passwords in plain text. Systems using unsalted hashes might be unsafe as well if using weak hash algorithms, however the attack would be very time-consuming.

-- 

no further details just yet

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1358865
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-5405
Comment 1 Swamp Workflow Management 2016-10-26 22:00:32 UTC
bugbot adjusting priority
Comment 2 Andreas Stieger 2017-11-20 22:39:17 UTC
Howard, could I bother you for a maintenance update for Leap for these bugs?
991201,997256,1007004,1020670,1051997,1069067,1069074
Comment 3 Bernhard Wiedemann 2017-12-05 11:40:05 UTC
This is an autogenerated message for OBS integration:
This bug (1007004) was mentioned in
https://build.opensuse.org/request/show/548604 42.2 / 389-ds
Comment 4 Bernhard Wiedemann 2017-12-06 14:40:05 UTC
This is an autogenerated message for OBS integration:
This bug (1007004) was mentioned in
https://build.opensuse.org/request/show/554810 42.2 / 389-ds
Comment 5 Andreas Stieger 2017-12-18 20:46:05 UTC
releasing, done. Thanks Howard
Comment 6 Swamp Workflow Management 2017-12-19 02:07:21 UTC
openSUSE-SU-2017:3362-1: An update that solves four vulnerabilities and has two fixes is now available.

Category: security (moderate)
Bug References: 1007004,1020670,1051997,1069067,1069074,997256
CVE References: CVE-2016-4992,CVE-2016-5405,CVE-2017-2668,CVE-2017-7551
Sources used:
openSUSE Leap 42.3 (src):    389-ds-1.3.4.5-8.1
openSUSE Leap 42.2 (src):    389-ds-1.3.4.5-5.5.1
Comment 7 Marcus Meissner 2018-02-16 07:47:52 UTC
released