Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-2668

Опубликовано: 22 июн. 2018
Источник: debian
EPSS Низкий

Описание

389-ds-base before versions 1.3.5.17 and 1.3.6.10 is vulnerable to an invalid pointer dereference in the way LDAP bind requests are handled. A remote unauthenticated attacker could use this flaw to make ns-slapd crash via a specially crafted LDAP bind request, resulting in denial of service.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
389-ds-basefixed1.3.5.17-1package
389-ds-basenot-affectedjessiepackage

Примечания

  • CentOS fix: https://git.centos.org/raw/rpms!389-ds-base!/c9e5dad69e2b497f118efac56f43cc6c74b6a695/SOURCES!0072-fix-for-cve-2017-2668-simple-return-text-if-suffix-n.patch

  • https://bugzilla.redhat.com/show_bug.cgi?id=1436575

EPSS

Процентиль: 91%
0.07615
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 7 лет назад

389-ds-base before versions 1.3.5.17 and 1.3.6.10 is vulnerable to an invalid pointer dereference in the way LDAP bind requests are handled. A remote unauthenticated attacker could use this flaw to make ns-slapd crash via a specially crafted LDAP bind request, resulting in denial of service.

CVSS3: 6.5
redhat
больше 8 лет назад

389-ds-base before versions 1.3.5.17 and 1.3.6.10 is vulnerable to an invalid pointer dereference in the way LDAP bind requests are handled. A remote unauthenticated attacker could use this flaw to make ns-slapd crash via a specially crafted LDAP bind request, resulting in denial of service.

CVSS3: 6.5
nvd
больше 7 лет назад

389-ds-base before versions 1.3.5.17 and 1.3.6.10 is vulnerable to an invalid pointer dereference in the way LDAP bind requests are handled. A remote unauthenticated attacker could use this flaw to make ns-slapd crash via a specially crafted LDAP bind request, resulting in denial of service.

CVSS3: 6.5
github
больше 3 лет назад

389-ds-base before versions 1.3.5.17 and 1.3.6.10 is vulnerable to an invalid pointer dereference in the way LDAP bind requests are handled. A remote unauthenticated attacker could use this flaw to make ns-slapd crash via a specially crafted LDAP bind request, resulting in denial of service.

oracle-oval
больше 8 лет назад

ELSA-2017-0920: 389-ds-base security and bug fix update (IMPORTANT)

EPSS

Процентиль: 91%
0.07615
Низкий