Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2025:7395

Опубликовано: 04 окт. 2025
Источник: rocky
Оценка: Moderate

Описание

Moderate: 389-ds-base security update

389 Directory Server is an LDAP version 3 (LDAPv3) compliant server. The base packages include the Lightweight Directory Access Protocol (LDAP) server and command-line utilities for server administration.

Security Fix(es):

  • 389-ds-base: null pointer dereference leads to denial of service (CVE-2025-2487)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
389-ds-basex86_648.el9_6389-ds-base-2.6.1-8.el9_6.x86_64.rpm
389-ds-base-libsx86_648.el9_6389-ds-base-libs-2.6.1-8.el9_6.x86_64.rpm
389-ds-base-snmpx86_648.el9_6389-ds-base-snmp-2.6.1-8.el9_6.x86_64.rpm
python3-lib389noarch8.el9_6python3-lib389-2.6.1-8.el9_6.noarch.rpm
python3-lib389noarch8.el9_6python3-lib389-2.6.1-8.el9_6.noarch.rpm
python3-lib389noarch8.el9_6python3-lib389-2.6.1-8.el9_6.noarch.rpm
python3-lib389noarch8.el9_6python3-lib389-2.6.1-8.el9_6.noarch.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 4.9
ubuntu
9 месяцев назад

A flaw was found in the 389-ds-base LDAP Server. This issue occurs when issuing a Modify DN LDAP operation through the ldap protocol, when the function return value is not tested and a NULL pointer is dereferenced. If a privileged user performs a ldap MODDN operation after a failed operation, it could lead to a Denial of Service (DoS) or system crash.

CVSS3: 4.9
redhat
9 месяцев назад

A flaw was found in the 389-ds-base LDAP Server. This issue occurs when issuing a Modify DN LDAP operation through the ldap protocol, when the function return value is not tested and a NULL pointer is dereferenced. If a privileged user performs a ldap MODDN operation after a failed operation, it could lead to a Denial of Service (DoS) or system crash.

CVSS3: 4.9
nvd
9 месяцев назад

A flaw was found in the 389-ds-base LDAP Server. This issue occurs when issuing a Modify DN LDAP operation through the ldap protocol, when the function return value is not tested and a NULL pointer is dereferenced. If a privileged user performs a ldap MODDN operation after a failed operation, it could lead to a Denial of Service (DoS) or system crash.

CVSS3: 4.9
debian
9 месяцев назад

A flaw was found in the 389-ds-base LDAP Server. This issue occurs whe ...

rocky
5 месяцев назад

Moderate: 389-ds-base security update