Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-3514

Опубликовано: 01 апр. 2021
Источник: redhat
CVSS3: 6.5

Описание

When using a sync_repl client in 389-ds-base, an authenticated attacker can cause a NULL pointer dereference using a specially crafted query, causing a crash.

A flaw was found In 389-ds-base. When the Content Synchronization plugin is enabled, an authenticated user can reach a NULL pointer dereference using a specially crafted query. This flaw allows an authenticated attacker to cause a denial of service. The highest threat from this vulnerability is to system availability.

Отчет

Red Hat Identity Management is affected by this flaw, as Content Synchronization is enabled by default.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6389-ds-baseOut of support scope
Red Hat Enterprise Linux 7389-ds-baseOut of support scope
Red Hat Enterprise Linux 9389-ds-baseNot affected
Red Hat Directory Server 11.3 for RHEL 8redhat-dsFixedRHSA-2022:095216.03.2022
Red Hat Directory Server 11.4 for RHEL 8redhat-dsFixedRHSA-2021:395525.10.2021
Red Hat Enterprise Linux 8389-dsFixedRHSA-2021:259529.06.2021
Red Hat Enterprise Linux 8.2 Extended Update Support389-dsFixedRHSA-2021:279621.07.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=1952907389-ds-base: sync_repl NULL pointer dereference in sync_create_state_control()

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 4 лет назад

When using a sync_repl client in 389-ds-base, an authenticated attacker can cause a NULL pointer dereference using a specially crafted query, causing a crash.

CVSS3: 6.5
nvd
около 4 лет назад

When using a sync_repl client in 389-ds-base, an authenticated attacker can cause a NULL pointer dereference using a specially crafted query, causing a crash.

CVSS3: 6.5
debian
около 4 лет назад

When using a sync_repl client in 389-ds-base, an authenticated attacke ...

suse-cvrf
около 4 лет назад

Security update for 389-ds

suse-cvrf
около 4 лет назад

Security update for 389-ds

6.5 Medium

CVSS3