Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:5513

Опубликовано: 07 апр. 2026
Источник: rocky
Оценка: Moderate

Описание

Moderate: 389-ds:1.4 security update

389 Directory Server is an LDAP version 3 (LDAPv3) compliant server. The base packages include the Lightweight Directory Access Protocol (LDAP) server and command-line utilities for server administration.

Security Fix(es):

  • 389-ds-base: 389-ds-base: Remote Code Execution and Denial of Service via heap buffer overflow (CVE-2025-14905)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
389-ds-basex86_6423.module+el8.10.0+40135+69dd2a79389-ds-base-1.4.3.39-23.module+el8.10.0+40135+69dd2a79.x86_64.rpm
389-ds-base-develx86_6423.module+el8.10.0+40135+69dd2a79389-ds-base-devel-1.4.3.39-23.module+el8.10.0+40135+69dd2a79.x86_64.rpm
389-ds-base-legacy-toolsx86_6423.module+el8.10.0+40135+69dd2a79389-ds-base-legacy-tools-1.4.3.39-23.module+el8.10.0+40135+69dd2a79.x86_64.rpm
389-ds-base-libsx86_6423.module+el8.10.0+40135+69dd2a79389-ds-base-libs-1.4.3.39-23.module+el8.10.0+40135+69dd2a79.x86_64.rpm
389-ds-base-snmpx86_6423.module+el8.10.0+40135+69dd2a79389-ds-base-snmp-1.4.3.39-23.module+el8.10.0+40135+69dd2a79.x86_64.rpm
python3-lib389noarch23.module+el8.10.0+40135+69dd2a79python3-lib389-1.4.3.39-23.module+el8.10.0+40135+69dd2a79.noarch.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 7.2
ubuntu
5 месяцев назад

A flaw was found in the 389-ds-base server. A heap buffer overflow vulnerability exists in the `schema_attr_enum_callback` function within the `schema.c` file. This occurs because the code incorrectly calculates the buffer size by summing alias string lengths without accounting for additional formatting characters. When a large number of aliases are processed, this oversight can lead to a heap overflow, potentially allowing a remote attacker to cause a Denial of Service (DoS) or achieve Remote Code Execution (RCE).

CVSS3: 7.2
redhat
5 месяцев назад

A flaw was found in the 389-ds-base server. A heap buffer overflow vulnerability exists in the `schema_attr_enum_callback` function within the `schema.c` file. This occurs because the code incorrectly calculates the buffer size by summing alias string lengths without accounting for additional formatting characters. When a large number of aliases are processed, this oversight can lead to a heap overflow, potentially allowing a remote attacker to cause a Denial of Service (DoS) or achieve Remote Code Execution (RCE).

CVSS3: 7.2
nvd
5 месяцев назад

A flaw was found in the 389-ds-base server. A heap buffer overflow vulnerability exists in the `schema_attr_enum_callback` function within the `schema.c` file. This occurs because the code incorrectly calculates the buffer size by summing alias string lengths without accounting for additional formatting characters. When a large number of aliases are processed, this oversight can lead to a heap overflow, potentially allowing a remote attacker to cause a Denial of Service (DoS) or achieve Remote Code Execution (RCE).

CVSS3: 7.2
debian
5 месяцев назад

A flaw was found in the 389-ds-base server. A heap buffer overflow vul ...

suse-cvrf
4 месяца назад

Security update for 389-ds