Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-8445

Опубликовано: 05 сент. 2024
Источник: redhat
CVSS3: 5.7
EPSS Низкий

Описание

The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios. In certain product versions, an authenticated user may cause a server crash while modifying userPassword using malformed input.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Directory Server 11redhat-ds:11/389-ds-baseNot affected
Red Hat Directory Server 12redhat-ds:12/389-ds-baseNot affected
Red Hat Enterprise Linux 10389-ds-baseNot affected
Red Hat Enterprise Linux 6389-ds-baseNot affected
Red Hat Enterprise Linux 8389-ds:1.4/389-ds-baseNot affected
Red Hat Enterprise Linux 9389-ds-baseNot affected
Red Hat Enterprise Linux 7 Extended Lifecycle Support389-ds-baseFixedRHSA-2024:743401.10.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=2310110389-ds-base: server crash while modifying `userPassword` using malformed input (Incomplete fix for CVE-2024-2199)

EPSS

Процентиль: 36%
0.00147
Низкий

5.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.7
ubuntu
12 месяцев назад

The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios. In certain product versions, an authenticated user may cause a server crash while modifying `userPassword` using malformed input.

CVSS3: 5.7
nvd
12 месяцев назад

The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios. In certain product versions, an authenticated user may cause a server crash while modifying `userPassword` using malformed input.

CVSS3: 5.7
debian
12 месяцев назад

The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all ...

CVSS3: 5.7
github
12 месяцев назад

The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios. In certain product versions, an authenticated user may cause a server crash while modifying `userPassword` using malformed input.

oracle-oval
10 месяцев назад

ELSA-2024-7434: 389-ds-base security update (MODERATE)

EPSS

Процентиль: 36%
0.00147
Низкий

5.7 Medium

CVSS3