Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-3657

Опубликовано: 28 мая 2024
Источник: redhat
CVSS3: 7.5

Описание

A flaw was found in 389-ds-base. A specially-crafted LDAP query can potentially cause a failure on the directory server, leading to a denial of service

Отчет

This vulnerability is categorized as an important severity issue rather than a critical one because, while it can cause a denial of service by stopping the directory service, it does not allow for remote code execution, privilege escalation, or data exfiltration. The impact is limited to service disruption, which can be mitigated by monitoring and automatic service restarts. Additionally, exploiting this vulnerability requires specific crafted packets, indicating that an attacker would need a certain level of knowledge and access to execute the attack, reducing the likelihood of widespread exploitation.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6389-ds-baseOut of support scope
Red Hat Directory Server 11.5 E4S for RHEL 8redhat-dsFixedRHSA-2025:163218.02.2025
Red Hat Directory Server 11.7 for RHEL 8redhat-dsFixedRHSA-2024:657611.09.2024
Red Hat Directory Server 11.8 for RHEL 8redhat-dsFixedRHSA-2024:420902.07.2024
Red Hat Directory Server 11.9 for RHEL 8redhat-dsFixedRHSA-2024:421002.07.2024
Red Hat Directory Server 12.2 EUS for RHEL 9redhat-dsFixedRHSA-2024:745801.10.2024
Red Hat Directory Server 12.4 for RHEL 9redhat-dsFixedRHSA-2024:409225.06.2024
Red Hat Enterprise Linux 7389-ds-baseFixedRHSA-2024:359104.06.2024
Red Hat Enterprise Linux 8389-dsFixedRHSA-2024:423502.07.2024
Red Hat Enterprise Linux 8.8 Extended Update Support389-dsFixedRHSA-2024:569021.08.2024

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=2274401389-ds-base: potential denial of service via specially crafted kerberos AS-REQ request

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 года назад

A flaw was found in 389-ds-base. A specially-crafted LDAP query can potentially cause a failure on the directory server, leading to a denial of service

CVSS3: 7.5
nvd
около 1 года назад

A flaw was found in 389-ds-base. A specially-crafted LDAP query can potentially cause a failure on the directory server, leading to a denial of service

CVSS3: 7.5
debian
около 1 года назад

A flaw was found in 389-ds-base. A specially-crafted LDAP query can po ...

CVSS3: 7.5
redos
11 месяцев назад

Уязвимость 389-ds-base

CVSS3: 7.5
fstec
около 1 года назад

Уязвимость сервера службы каталогов 389 Directory Server, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю вызвать отказ в обслуживании

7.5 High

CVSS3

Уязвимость CVE-2024-3657