CVE-2018-1337

NameCVE-2018-1337
DescriptionIn Apache Directory LDAP API before 1.0.2, a bug in the way the SSL Filter was setup made it possible for another thread to use the connection before the TLS layer has been established, if the connection has already been used and put back in a pool of connections, leading to leaking any information contained in this request (including the credentials when sending a BIND request).
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
apache-directory-api (PTS)bullseye1.0.0-2vulnerable
bookworm2.1.2-1fixed
forky, sid, trixie2.1.2-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
apache-directory-apisource(unstable)2.1.2-1

Notes

https://lists.apache.org/thread/lrfz3057jbz6ssyg7scmcrpx46qopcm5

Search for package or bug name: Reporting problems