Описание
A flaw was found in slapi-nis in versions before 0.56.7. A NULL pointer dereference during the parsing of the Binding DN could allow an unauthenticated attacker to crash the 389-ds-base directory server. The highest threat from this vulnerability is to system availability.
A flaw was found in slapi-nis. A NULL pointer dereference during the parsing of the Binding DN could allow an unauthenticated attacker to crash the 389-ds-base directory server. The highest threat from this vulnerability is to system availability.
Отчет
This vulnerability affects Directory Server with the Schema Compatibility plugin "slapi-nis". To verify if an instance is configured with Schema Compatibility: $ ldapsearch -b 'cn=Schema Compatibility,cn=plugins,cn=config' -s base Red Hat Identity Management is affected by this flaw.
Меры по смягчению последствий
Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update as soon as possible.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 6 | slapi-nis | Out of support scope | ||
Red Hat Enterprise Linux 9 | slapi-nis | Not affected | ||
Red Hat Enterprise Linux 7 | slapi-nis | Fixed | RHSA-2021:2032 | 19.05.2021 |
Red Hat Enterprise Linux 8 | idm | Fixed | RHSA-2021:1983 | 18.05.2021 |
Red Hat Enterprise Linux 8.1 Extended Update Support | idm | Fixed | RHSA-2021:2027 | 19.05.2021 |
Red Hat Enterprise Linux 8.2 Extended Update Support | idm | Fixed | RHSA-2021:2026 | 19.05.2021 |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
A flaw was found in slapi-nis in versions before 0.56.7. A NULL pointer dereference during the parsing of the Binding DN could allow an unauthenticated attacker to crash the 389-ds-base directory server. The highest threat from this vulnerability is to system availability.
A flaw was found in slapi-nis in versions before 0.56.7. A NULL pointer dereference during the parsing of the Binding DN could allow an unauthenticated attacker to crash the 389-ds-base directory server. The highest threat from this vulnerability is to system availability.
A flaw was found in slapi-nis in versions before 0.56.7. A NULL pointe ...
A flaw was found in slapi-nis in versions before 0.56.7. A NULL pointer dereference during the parsing of the Binding DN could allow an unauthenticated attacker to crash the 389-ds-base directory server. The highest threat from this vulnerability is to system availability.
7.5 High
CVSS3