Description
A denial of service vulnerability was found in 389-ds-base ldap server. This issue may allow an authenticated user to cause a server crash while modifying `userPassword` using malformed input.
Problem types
Product status
Any version before 3.1.1
8060020250210084424.0ca98e7e (rpm) before *
8090020240606122459.91529cd0 (rpm) before *
8100020240604161237.37ed7c03 (rpm) before *
9040020240604143706.1674d574 (rpm) before *
0:1.3.11.1-5.el7_9 (rpm) before *
8100020240613122040.25e700aa (rpm) before *
8080020240807050952.6dbb3803 (rpm) before *
0:2.4.5-8.el9_4 (rpm) before *
0:2.2.4-9.el9_2 (rpm) before *
Timeline
| 2024-03-05: | Reported to Red Hat. |
| 2024-05-28: | Made public. |
References
access.redhat.com/errata/RHSA-2024:3591 (RHSA-2024:3591)
access.redhat.com/errata/RHSA-2024:3837 (RHSA-2024:3837)
access.redhat.com/errata/RHSA-2024:4092 (RHSA-2024:4092)
access.redhat.com/errata/RHSA-2024:4209 (RHSA-2024:4209)
access.redhat.com/errata/RHSA-2024:4210 (RHSA-2024:4210)
access.redhat.com/errata/RHSA-2024:4235 (RHSA-2024:4235)
access.redhat.com/errata/RHSA-2024:4633 (RHSA-2024:4633)
access.redhat.com/security/cve/CVE-2024-2199
bugzilla.redhat.com/show_bug.cgi?id=2267976 (RHBZ#2267976)
lists.debian.org/debian-lts-announce/2025/01/msg00015.html
access.redhat.com/errata/RHSA-2024:3591 (RHSA-2024:3591)
access.redhat.com/errata/RHSA-2024:3837 (RHSA-2024:3837)
access.redhat.com/errata/RHSA-2024:4092 (RHSA-2024:4092)
access.redhat.com/errata/RHSA-2024:4209 (RHSA-2024:4209)
access.redhat.com/errata/RHSA-2024:4210 (RHSA-2024:4210)
access.redhat.com/errata/RHSA-2024:4235 (RHSA-2024:4235)
access.redhat.com/errata/RHSA-2024:4633 (RHSA-2024:4633)
access.redhat.com/errata/RHSA-2024:5690 (RHSA-2024:5690)
access.redhat.com/errata/RHSA-2025:1632 (RHSA-2025:1632)
access.redhat.com/security/cve/CVE-2024-2199
bugzilla.redhat.com/show_bug.cgi?id=2267976 (RHBZ#2267976)
www.port389.org/docs/389ds/releases/release-3-1-1.html