Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-4091

Опубликовано: 27 янв. 2022
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A double-free was found in the way 389-ds-base handles virtual attributes context in persistent searches. An attacker could send a series of search requests, forcing the server to behave unexpectedly, and crash.

A double free was found in the way 389-ds-base handles virtual attributes context in persistent searches. An attacker could send a series of search requests, forcing the server to behave unexpectedly, and crash.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6389-ds-baseNot affected
Red Hat Enterprise Linux 9389-ds-baseNot affected
Red Hat Directory Server 11.3 for RHEL 8redhat-dsFixedRHSA-2022:095216.03.2022
Red Hat Enterprise Linux 7389-ds-baseFixedRHSA-2022:062822.02.2022
Red Hat Enterprise Linux 8389-dsFixedRHSA-2022:088915.03.2022
Red Hat Enterprise Linux 8.4 Extended Update Support389-dsFixedRHSA-2022:141019.04.2022

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-415
https://bugzilla.redhat.com/show_bug.cgi?id=2030307389-ds-base: double free of the virtual attribute context in persistent search

EPSS

Процентиль: 46%
0.00236
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 4 года назад

A double-free was found in the way 389-ds-base handles virtual attributes context in persistent searches. An attacker could send a series of search requests, forcing the server to behave unexpectedly, and crash.

CVSS3: 7.5
nvd
почти 4 года назад

A double-free was found in the way 389-ds-base handles virtual attributes context in persistent searches. An attacker could send a series of search requests, forcing the server to behave unexpectedly, and crash.

CVSS3: 7.5
debian
почти 4 года назад

A double-free was found in the way 389-ds-base handles virtual attribu ...

rocky
почти 4 года назад

Low: 389-ds:1.4 security and bug fix update

CVSS3: 7.5
github
почти 4 года назад

A double-free was found in the way 389-ds-base handles virtual attributes context in persistent searches. An attacker could send a series of search requests, forcing the server to behave unexpectedly, and crash.

EPSS

Процентиль: 46%
0.00236
Низкий

7.5 High

CVSS3