Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-6220

Опубликовано: 16 апр. 2026
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2026-6220: 389-ds-base security update (MODERATE)

[1.3.11.1-5.0.7]

  • Security fix for CVE-2025-14905 [Orabug: 39146844]

[1.3.11.1-5.0.5]

  • Allow Uniqueness plugin to search uniqueness attributes using custom matching rules [Orabug: 38388205]

Обновленные пакеты

Oracle Linux 7

Oracle Linux x86_64

389-ds-base

1.3.11.1-5.0.7.el7_9

389-ds-base-devel

1.3.11.1-5.0.7.el7_9

389-ds-base-libs

1.3.11.1-5.0.7.el7_9

389-ds-base-snmp

1.3.11.1-5.0.7.el7_9

Связанные CVE

Связанные уязвимости

CVSS3: 7.2
ubuntu
5 месяцев назад

A flaw was found in the 389-ds-base server. A heap buffer overflow vulnerability exists in the `schema_attr_enum_callback` function within the `schema.c` file. This occurs because the code incorrectly calculates the buffer size by summing alias string lengths without accounting for additional formatting characters. When a large number of aliases are processed, this oversight can lead to a heap overflow, potentially allowing a remote attacker to cause a Denial of Service (DoS) or achieve Remote Code Execution (RCE).

CVSS3: 7.2
redhat
5 месяцев назад

A flaw was found in the 389-ds-base server. A heap buffer overflow vulnerability exists in the `schema_attr_enum_callback` function within the `schema.c` file. This occurs because the code incorrectly calculates the buffer size by summing alias string lengths without accounting for additional formatting characters. When a large number of aliases are processed, this oversight can lead to a heap overflow, potentially allowing a remote attacker to cause a Denial of Service (DoS) or achieve Remote Code Execution (RCE).

CVSS3: 7.2
nvd
5 месяцев назад

A flaw was found in the 389-ds-base server. A heap buffer overflow vulnerability exists in the `schema_attr_enum_callback` function within the `schema.c` file. This occurs because the code incorrectly calculates the buffer size by summing alias string lengths without accounting for additional formatting characters. When a large number of aliases are processed, this oversight can lead to a heap overflow, potentially allowing a remote attacker to cause a Denial of Service (DoS) or achieve Remote Code Execution (RCE).

CVSS3: 7.2
debian
5 месяцев назад

A flaw was found in the 389-ds-base server. A heap buffer overflow vul ...

suse-cvrf
4 месяца назад

Security update for 389-ds