Описание
A vulnerability was discovered in the 389 Directory Server that allows an unauthenticated attacker with network access to the LDAP port to cause a denial of service. The denial of service is triggered by a single message sent over a TCP connection, no bind or other authentication is required. The message triggers a segmentation fault that results in slapd crashing.
A vulnerability was found in the 389 Directory Server that allows an unauthenticated attacker with network access to the LDAP port to cause a denial of service. The denial of service is triggered by a single message sent over a TCP connection. No bind or other authentication is required. This message triggers a segmentation fault that results in slapd crashing.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Directory Server 12 | redhat-ds:12/389-ds-base | Affected | ||
Red Hat Enterprise Linux 6 | 389-ds-base | Out of support scope | ||
Red Hat Directory Server 11.5 for RHEL 8 | redhat-ds | Fixed | RHSA-2022:2210 | 11.05.2022 |
Red Hat Enterprise Linux 7 | 389-ds-base | Fixed | RHSA-2022:5239 | 28.06.2022 |
Red Hat Enterprise Linux 8 | 389-ds | Fixed | RHSA-2022:5823 | 02.08.2022 |
Red Hat Enterprise Linux 8.4 Extended Update Support | 389-ds | Fixed | RHSA-2022:5620 | 19.07.2022 |
Red Hat Enterprise Linux 9 | 389-ds-base | Fixed | RHSA-2022:8162 | 15.11.2022 |
Red Hat Enterprise Linux 9.0 Extended Update Support | 389-ds-base | Fixed | RHSA-2022:8976 | 13.12.2022 |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
A vulnerability was discovered in the 389 Directory Server that allows an unauthenticated attacker with network access to the LDAP port to cause a denial of service. The denial of service is triggered by a single message sent over a TCP connection, no bind or other authentication is required. The message triggers a segmentation fault that results in slapd crashing.
A vulnerability was discovered in the 389 Directory Server that allows an unauthenticated attacker with network access to the LDAP port to cause a denial of service. The denial of service is triggered by a single message sent over a TCP connection, no bind or other authentication is required. The message triggers a segmentation fault that results in slapd crashing.
A vulnerability was discovered in the 389 Directory Server that allows ...
A vulnerability was discovered in the 389 Directory Server that allows an unauthenticated attacker with network access to the LDAP port to cause a denial of service. The denial of service is triggered by a single message sent over a TCP connection, no bind or other authentication is required. The message triggers a segmentation fault that results in slapd crashing.
Уязвимость сервера службы каталогов 389 Directory Server, связанная с ошибками при освобождении ресурсов, позволяющая нарушителю вызвать отказ в обслуживании
7.5 High
CVSS3