PT-2019-11541 · Univention · Univention Corporate Server

·

CVE-2019-1010283

·

Published

2019-07-17

·

Updated

2023-09-21

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Univention Corporate Server univention-directory-notifier versions 12.0.1-3 and earlier
Description: The issue affects the function data on connection() in src/callback.c, allowing intentional information exposure through network connectivity, which may lead to loss of confidentiality.
Recommendations: For versions 12.0.1-3 and earlier, update to version 12.0.1-4 or later to resolve the issue. As a temporary workaround, consider restricting network connectivity to minimize the risk of exploitation.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-1010283

Affected Products

Univention Corporate Server