Описание
When using a sync_repl client in 389-ds-base, an authenticated attacker can cause a NULL pointer dereference using a specially crafted query, causing a crash.
Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
389-ds-base | fixed | 1.4.4.11-2 | package | |
389-ds-base | no-dsa | stretch | package |
Примечания
https://github.com/389ds/389-ds-base/issues/4711
EPSS
Процентиль: 29%
0.00103
Низкий
Связанные уязвимости
CVSS3: 6.5
ubuntu
около 4 лет назад
When using a sync_repl client in 389-ds-base, an authenticated attacker can cause a NULL pointer dereference using a specially crafted query, causing a crash.
CVSS3: 6.5
redhat
больше 4 лет назад
When using a sync_repl client in 389-ds-base, an authenticated attacker can cause a NULL pointer dereference using a specially crafted query, causing a crash.
CVSS3: 6.5
nvd
около 4 лет назад
When using a sync_repl client in 389-ds-base, an authenticated attacker can cause a NULL pointer dereference using a specially crafted query, causing a crash.
EPSS
Процентиль: 29%
0.00103
Низкий