Описание
A flaw was found in 389 Directory Server. The SMD5 password storage plugin performs unsigned integer underflow when computing salt length from a crafted password hash shorter than 16 bytes, causing a buffer over-read that crashes the LDAP server during authentication.
Отчет
Red Hat rates this issue as Moderate impact. The SMD5 password storage plugin in 389-ds-base underflows when computing salt length from a stored hash shorter than 16 bytes, causing the server to crash during LDAP BIND. NVD rates 6.5 (PR:L); Red Hat rates 4.9 (PR:H) because planting the crafted hash requires Directory Manager privileges or the non-default nsslapd-allow-hashed-passwords setting. Once planted, the crash re-triggers on every bind to the poisoned account until the hash is removed offline. This is a missed variant of CVE-2024-5953, which patched md5_pwd.c and pbkdf2_pwd.c but not smd5_pwd.c.
Меры по смягчению последствий
Disable nsslapd-allow-hashed-passwords (default: off) to prevent non-DM users from setting pre-hashed passwords. Restrict Directory Manager credentials; limit DM access to management networks and audit DM operations via nsslapd-auditlog. Monitor for suspicious userPassword modifications. Migrate stored passwords from {SMD5} to {PBKDF2_SHA256} to eliminate the vulnerable code path for existing accounts.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Directory Server 11 | redhat-ds:11/389-ds-base | Fix deferred | ||
| Red Hat Directory Server 12 | redhat-ds:12/389-ds-base | Fix deferred | ||
| Red Hat Directory Server 13 | 389-ds-base | Fix deferred | ||
| Red Hat Enterprise Linux 10 | 389-ds-base | Fix deferred | ||
| Red Hat Enterprise Linux 6 | 389-ds-base | Out of support scope | ||
| Red Hat Enterprise Linux 7 | 389-ds-base | Fix deferred | ||
| Red Hat Enterprise Linux 8 | 389-ds-base | Fix deferred | ||
| Red Hat Enterprise Linux 9 | 389-ds-base | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
4.9 Medium
CVSS3
Связанные уязвимости
A flaw was found in 389 Directory Server. The SMD5 password storage plugin performs unsigned integer underflow when computing salt length from a crafted password hash shorter than 16 bytes, causing a buffer over-read that crashes the LDAP server during authentication.
A flaw was found in 389 Directory Server. The SMD5 password storage plugin performs unsigned integer underflow when computing salt length from a crafted password hash shorter than 16 bytes, causing a buffer over-read that crashes the LDAP server during authentication.
A flaw was found in 389 Directory Server. The SMD5 password storage pl ...
A flaw was found in 389 Directory Server. The SMD5 password storage plugin performs unsigned integer underflow when computing salt length from a crafted password hash shorter than 16 bytes, causing a buffer over-read that crashes the LDAP server during authentication.
EPSS
4.9 Medium
CVSS3