Candidate: CVE-2016-5405 PublicDate: 2017-06-08 19:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5405 Description: 389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server 6 through 7, and Red Hat Enterprise Linux Workstation 6 through 7 allows remote attackers to obtain user passwords. Ubuntu-Description: Notes: sbeattie> affects systems where passwords are stored in plain text or unsalted hashs using weak algorithms leosilva> code in trusty is quite different from patch. Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=842121 https://bugzilla.redhat.com/show_bug.cgi?id=1358865 Priority: low Discovered-by: William Brown Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_389-ds-base: other: https://pagure.io/389-ds-base/c/762219a35005914c6c088d915ac9346ce7e28512 upstream_389-ds-base: needs-triage precise_389-ds-base: ignored (reached end-of-life) precise/esm_389-ds-base: DNE (precise was needs-triage) trusty_389-ds-base: not-affected (code not present) trusty/esm_389-ds-base: DNE (trusty was not-affected [code not present]) vivid/stable-phone-overlay_389-ds-base: DNE vivid/ubuntu-core_389-ds-base: DNE xenial_389-ds-base: not-affected (code not present) yakkety_389-ds-base: ignored (reached end-of-life) zesty_389-ds-base: ignored (reached end-of-life) artful_389-ds-base: not-affected (1.3.5.15-1) bionic_389-ds-base: not-affected (1.3.5.15-1) cosmic_389-ds-base: not-affected (1.3.5.15-1) devel_389-ds-base: not-affected (1.3.5.15-1)