Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-0918

Опубликовано: 16 мар. 2022
Источник: debian
EPSS Низкий

Описание

A vulnerability was discovered in the 389 Directory Server that allows an unauthenticated attacker with network access to the LDAP port to cause a denial of service. The denial of service is triggered by a single message sent over a TCP connection, no bind or other authentication is required. The message triggers a segmentation fault that results in slapd crashing.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
389-ds-basefixed2.0.15-1.1package

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=2055815

  • https://github.com/389ds/389-ds-base/issues/5242

  • https://github.com/389ds/389-ds-base/commit/caad47ab207d7c5d61521ec4d33091db559c315a (master)

  • https://github.com/389ds/389-ds-base/commit/f46ab49c9f06b503f5ec8147f2c01dcacdb6a375 (389-ds-base-2.0.16)

EPSS

Процентиль: 90%
0.05358
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 3 лет назад

A vulnerability was discovered in the 389 Directory Server that allows an unauthenticated attacker with network access to the LDAP port to cause a denial of service. The denial of service is triggered by a single message sent over a TCP connection, no bind or other authentication is required. The message triggers a segmentation fault that results in slapd crashing.

CVSS3: 7.5
redhat
больше 3 лет назад

A vulnerability was discovered in the 389 Directory Server that allows an unauthenticated attacker with network access to the LDAP port to cause a denial of service. The denial of service is triggered by a single message sent over a TCP connection, no bind or other authentication is required. The message triggers a segmentation fault that results in slapd crashing.

CVSS3: 7.5
nvd
больше 3 лет назад

A vulnerability was discovered in the 389 Directory Server that allows an unauthenticated attacker with network access to the LDAP port to cause a denial of service. The denial of service is triggered by a single message sent over a TCP connection, no bind or other authentication is required. The message triggers a segmentation fault that results in slapd crashing.

CVSS3: 7.5
github
больше 3 лет назад

A vulnerability was discovered in the 389 Directory Server that allows an unauthenticated attacker with network access to the LDAP port to cause a denial of service. The denial of service is triggered by a single message sent over a TCP connection, no bind or other authentication is required. The message triggers a segmentation fault that results in slapd crashing.

CVSS3: 7.5
fstec
больше 3 лет назад

Уязвимость сервера службы каталогов 389 Directory Server, связанная с ошибками при освобождении ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 90%
0.05358
Низкий