Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2024:5192

Опубликовано: 21 авг. 2024
Источник: rocky
Оценка: Moderate

Описание

Moderate: 389-ds-base security update

389 Directory Server is an LDAP version 3 (LDAPv3) compliant server. The base packages include the Lightweight Directory Access Protocol (LDAP) server and command-line utilities for server administration.

Security Fix(es):

  • 389-ds-base: Malformed userPassword hash may cause Denial of Service (CVE-2024-5953)

  • 389-ds-base: unauthenticated user can trigger a DoS by sending a specific extended search request (CVE-2024-6237)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
389-ds-basex86_649.el9_4389-ds-base-2.4.5-9.el9_4.x86_64.rpm
389-ds-base-libsx86_649.el9_4389-ds-base-libs-2.4.5-9.el9_4.x86_64.rpm
python3-lib389noarch9.el9_4python3-lib389-2.4.5-9.el9_4.noarch.rpm

Показывать по

Связанные CVE

Связанные уязвимости

oracle-oval
около 1 года назад

ELSA-2024-5192: 389-ds-base security update (MODERATE)

CVSS3: 6.5
ubuntu
около 1 года назад

A flaw was found in the 389 Directory Server. This flaw allows an unauthenticated user to cause a systematic server crash while sending a specific extended search request, leading to a denial of service.

CVSS3: 6.5
redhat
около 1 года назад

A flaw was found in the 389 Directory Server. This flaw allows an unauthenticated user to cause a systematic server crash while sending a specific extended search request, leading to a denial of service.

CVSS3: 6.5
nvd
около 1 года назад

A flaw was found in the 389 Directory Server. This flaw allows an unauthenticated user to cause a systematic server crash while sending a specific extended search request, leading to a denial of service.

CVSS3: 6.5
debian
около 1 года назад

A flaw was found in the 389 Directory Server. This flaw allows an unau ...