Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-3480

Опубликовано: 17 мая 2021
Источник: redhat
CVSS3: 7.5

Описание

A flaw was found in slapi-nis in versions before 0.56.7. A NULL pointer dereference during the parsing of the Binding DN could allow an unauthenticated attacker to crash the 389-ds-base directory server. The highest threat from this vulnerability is to system availability.

A flaw was found in slapi-nis. A NULL pointer dereference during the parsing of the Binding DN could allow an unauthenticated attacker to crash the 389-ds-base directory server. The highest threat from this vulnerability is to system availability.

Отчет

This vulnerability affects Directory Server with the Schema Compatibility plugin "slapi-nis". To verify if an instance is configured with Schema Compatibility: $ ldapsearch -b 'cn=Schema Compatibility,cn=plugins,cn=config' -s base Red Hat Identity Management is affected by this flaw.

Меры по смягчению последствий

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update as soon as possible.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6slapi-nisOut of support scope
Red Hat Enterprise Linux 9slapi-nisNot affected
Red Hat Enterprise Linux 7slapi-nisFixedRHSA-2021:203219.05.2021
Red Hat Enterprise Linux 8idmFixedRHSA-2021:198318.05.2021
Red Hat Enterprise Linux 8.1 Extended Update SupportidmFixedRHSA-2021:202719.05.2021
Red Hat Enterprise Linux 8.2 Extended Update SupportidmFixedRHSA-2021:202619.05.2021

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=1944640slapi-nis: NULL dereference (DoS) with specially crafted Binding DN

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 4 лет назад

A flaw was found in slapi-nis in versions before 0.56.7. A NULL pointer dereference during the parsing of the Binding DN could allow an unauthenticated attacker to crash the 389-ds-base directory server. The highest threat from this vulnerability is to system availability.

CVSS3: 7.5
nvd
около 4 лет назад

A flaw was found in slapi-nis in versions before 0.56.7. A NULL pointer dereference during the parsing of the Binding DN could allow an unauthenticated attacker to crash the 389-ds-base directory server. The highest threat from this vulnerability is to system availability.

CVSS3: 7.5
debian
около 4 лет назад

A flaw was found in slapi-nis in versions before 0.56.7. A NULL pointe ...

rocky
почти 4 года назад

Important: idm:DL1 security update

github
около 3 лет назад

A flaw was found in slapi-nis in versions before 0.56.7. A NULL pointer dereference during the parsing of the Binding DN could allow an unauthenticated attacker to crash the 389-ds-base directory server. The highest threat from this vulnerability is to system availability.

7.5 High

CVSS3