Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-14648

Опубликовано: 28 сент. 2018
Источник: debian
EPSS Средний

Описание

A flaw was found in 389 Directory Server. A specially crafted search query could lead to excessive CPU consumption in the do_search() function. An unauthenticated attacker could use this flaw to provoke a denial of service.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
389-ds-basefixed1.4.0.18-1package
389-ds-baseno-dsastretchpackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=1630668

  • https://pagure.io/389-ds-base/c/a49bd03d6 (1.4.0.17)

  • 1.3.7: https://pagure.io/389-ds-base/c/c8ec6e58c

  • 1.3.8: https://pagure.io/389-ds-base/c/5fc374b43

  • Note that these patches are incomplete and cause a regression (crash). Bundle with

  • https://pagure.io/389-ds-base/c/a6369790c (1.4.0.17)

  • 1.3.7: https://pagure.io/389-ds-base/c/722a6f867

  • 1.3.8: https://pagure.io/389-ds-base/c/bdb1af66c

  • see https://pagure.io/389-ds-base/issue/49969

EPSS

Процентиль: 93%
0.10171
Средний

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 7 лет назад

A flaw was found in 389 Directory Server. A specially crafted search query could lead to excessive CPU consumption in the do_search() function. An unauthenticated attacker could use this flaw to provoke a denial of service.

CVSS3: 7.5
redhat
около 7 лет назад

A flaw was found in 389 Directory Server. A specially crafted search query could lead to excessive CPU consumption in the do_search() function. An unauthenticated attacker could use this flaw to provoke a denial of service.

CVSS3: 7.5
nvd
около 7 лет назад

A flaw was found in 389 Directory Server. A specially crafted search query could lead to excessive CPU consumption in the do_search() function. An unauthenticated attacker could use this flaw to provoke a denial of service.

CVSS3: 7.5
github
больше 3 лет назад

A flaw was found in 389 Directory Server. A specially crafted search query could lead to excessive CPU consumption in the do_search() function. An unauthenticated attacker could use this flaw to provoke a denial of service.

oracle-oval
около 7 лет назад

ELSA-2018-3127: 389-ds-base security, bug fix, and enhancement update (MODERATE)

EPSS

Процентиль: 93%
0.10171
Средний