Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-2487

Опубликовано: 18 мар. 2025
Источник: redhat
CVSS3: 4.9
EPSS Низкий

Описание

A flaw was found in the 389-ds-base LDAP Server. This issue occurs when issuing a Modify DN LDAP operation through the ldap protocol, when the function return value is not tested and a NULL pointer is dereferenced. If a privileged user performs a ldap MODDN operation after a failed operation, it could lead to a Denial of Service (DoS) or system crash.

Отчет

Red Hat rates this as a Moderate severity since the impact is limited to privileged users who can perform the operations, leading to an impact on server Availability. This issue is not reproducible in Red Hat Enterprise Linux (RHEL) 10 due to the way the RHEL 10 database write operations are serialized, therefore, it is not affected. 389-ds-base has been fixed in RHEL 9.5. Starting from RHDS 12.5, it uses 389-ds-base from RHEL-9.5. Hence, it's actually not-affected and fix will be picked after rebase from RHEL-9.5.

Меры по смягчению последствий

Currently, no mitigation is available for this vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Directory Server 12redhat-ds:12/389-ds-baseNot affected
Red Hat Enterprise Linux 10389-ds-baseNot affected
Red Hat Enterprise Linux 6389-ds-baseOut of support scope
Red Hat Enterprise Linux 7389-ds-baseOut of support scope
Red Hat Enterprise Linux 8389-ds:1.4/389-ds-baseOut of support scope
Red Hat Directory Server 12.4 EUS for RHEL 9redhat-dsFixedRHSA-2025:367008.04.2025
Red Hat Enterprise Linux 9389-ds-baseFixedRHSA-2025:449106.05.2025
Red Hat Enterprise Linux 9389-ds-baseFixedRHSA-2025:739513.05.2025
Red Hat Enterprise Linux 9.4 Extended Update Support389-ds-baseFixedRHSA-2025:366308.04.2025

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2353071389-ds-base: null pointer dereference leads to denial of service

EPSS

Процентиль: 36%
0.00148
Низкий

4.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.9
ubuntu
5 месяцев назад

A flaw was found in the 389-ds-base LDAP Server. This issue occurs when issuing a Modify DN LDAP operation through the ldap protocol, when the function return value is not tested and a NULL pointer is dereferenced. If a privileged user performs a ldap MODDN operation after a failed operation, it could lead to a Denial of Service (DoS) or system crash.

CVSS3: 4.9
nvd
5 месяцев назад

A flaw was found in the 389-ds-base LDAP Server. This issue occurs when issuing a Modify DN LDAP operation through the ldap protocol, when the function return value is not tested and a NULL pointer is dereferenced. If a privileged user performs a ldap MODDN operation after a failed operation, it could lead to a Denial of Service (DoS) or system crash.

CVSS3: 4.9
debian
5 месяцев назад

A flaw was found in the 389-ds-base LDAP Server. This issue occurs whe ...

CVSS3: 4.9
github
5 месяцев назад

A flaw was found in the 389-ds-base LDAP Server. This issue occurs when issuing a Modify DN LDAP operation through the ldap protocol, when the function return value is not tested and a NULL pointer is dereferenced. If a privileged user performs a ldap MODDN operation after a failed operation, it could lead to a Denial of Service (DoS) or system crash.

oracle-oval
3 месяца назад

ELSA-2025-7395: 389-ds-base security update (MODERATE)

EPSS

Процентиль: 36%
0.00148
Низкий

4.9 Medium

CVSS3