Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-2850

Опубликовано: 04 авг. 2022
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

A flaw was found In 389-ds-base. When the Content Synchronization plugin is enabled, an authenticated user can reach a NULL pointer dereference using a specially crafted query. This flaw allows an authenticated attacker to cause a denial of service. This CVE is assigned against an incomplete fix of CVE-2021-3514.

A flaw was found In 389-ds-base. When the Content Synchronization plugin is enabled, an authenticated user can reach a NULL pointer dereference using a specially crafted query. This flaw allows an authenticated attacker to cause a denial of service.

Отчет

This CVE is assigned against an incomplete fix of CVE-2021-3514.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6389-ds-baseOut of support scope
Red Hat Directory Server 11.5 for RHEL 8redhat-dsFixedRHSA-2022:888607.12.2022
Red Hat Directory Server 12.0 for RHEL 9redhat-dsFixedRHSA-2023:047926.01.2023
Red Hat Enterprise Linux 7389-ds-baseFixedRHSA-2022:708725.10.2022
Red Hat Enterprise Linux 8389-dsFixedRHSA-2022:713325.10.2022
Red Hat Enterprise Linux 8.4 Extended Update Support389-dsFixedRHSA-2022:868029.11.2022
Red Hat Enterprise Linux 9389-ds-baseFixedRHSA-2022:816215.11.2022
Red Hat Enterprise Linux 9.0 Extended Update Support389-ds-baseFixedRHSA-2022:897613.12.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-476

EPSS

Процентиль: 46%
0.00236
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 3 года назад

A flaw was found In 389-ds-base. When the Content Synchronization plugin is enabled, an authenticated user can reach a NULL pointer dereference using a specially crafted query. This flaw allows an authenticated attacker to cause a denial of service. This CVE is assigned against an incomplete fix of CVE-2021-3514.

CVSS3: 6.5
nvd
почти 3 года назад

A flaw was found In 389-ds-base. When the Content Synchronization plugin is enabled, an authenticated user can reach a NULL pointer dereference using a specially crafted query. This flaw allows an authenticated attacker to cause a denial of service. This CVE is assigned against an incomplete fix of CVE-2021-3514.

CVSS3: 6.5
debian
почти 3 года назад

A flaw was found In 389-ds-base. When the Content Synchronization plug ...

suse-cvrf
почти 3 года назад

Security update for 389-ds

suse-cvrf
почти 3 года назад

Security update for 389-ds

EPSS

Процентиль: 46%
0.00236
Низкий

6.5 Medium

CVSS3