Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-14648

Опубликовано: 21 сент. 2018
Источник: redhat
CVSS3: 7.5
EPSS Средний

Описание

A flaw was found in 389 Directory Server. A specially crafted search query could lead to excessive CPU consumption in the do_search() function. An unauthenticated attacker could use this flaw to provoke a denial of service.

It was found that a specially crafted search query could lead to excessive CPU consumption in the do_search() function. An unauthenticated attacker could use this flaw to provoke a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6389-ds-baseWill not fix
Red Hat Enterprise Linux 8389-ds-baseNot affected
Red Hat Enterprise Linux 7389-ds-baseFixedRHSA-2018:312730.10.2018
Red Hat Enterprise Linux 7.5 Extended Update Support389-ds-baseFixedRHSA-2018:350706.11.2018

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1630668389-ds-base: Mishandled search requests in servers/slapd/search.c:do_search() allows for denial of service

EPSS

Процентиль: 93%
0.10171
Средний

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 7 лет назад

A flaw was found in 389 Directory Server. A specially crafted search query could lead to excessive CPU consumption in the do_search() function. An unauthenticated attacker could use this flaw to provoke a denial of service.

CVSS3: 7.5
nvd
около 7 лет назад

A flaw was found in 389 Directory Server. A specially crafted search query could lead to excessive CPU consumption in the do_search() function. An unauthenticated attacker could use this flaw to provoke a denial of service.

CVSS3: 7.5
debian
около 7 лет назад

A flaw was found in 389 Directory Server. A specially crafted search q ...

CVSS3: 7.5
github
больше 3 лет назад

A flaw was found in 389 Directory Server. A specially crafted search query could lead to excessive CPU consumption in the do_search() function. An unauthenticated attacker could use this flaw to provoke a denial of service.

oracle-oval
около 7 лет назад

ELSA-2018-3127: 389-ds-base security, bug fix, and enhancement update (MODERATE)

EPSS

Процентиль: 93%
0.10171
Средний

7.5 High

CVSS3