Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 8

Количество 8

github логотип

GHSA-c65q-p9xj-798w

около 4 лет назад

In 389-ds-base up to version 1.4.1.2, requests are handled by workers threads. Each sockets will be waited by the worker for at most 'ioblocktimeout' seconds. However this timeout applies only for un-encrypted requests. Connections using SSL/TLS are not taking this timeout into account during reads, and may hang longer.An unauthenticated attacker could repeatedly create hanging LDAP requests to hang all the workers, resulting in a Denial of Service.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2019-3883

больше 7 лет назад

In 389-ds-base up to version 1.4.1.2, requests are handled by workers threads. Each sockets will be waited by the worker for at most 'ioblocktimeout' seconds. However this timeout applies only for un-encrypted requests. Connections using SSL/TLS are not taking this timeout into account during reads, and may hang longer.An unauthenticated attacker could repeatedly create hanging LDAP requests to hang all the workers, resulting in a Denial of Service.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2019-3883

больше 7 лет назад

In 389-ds-base up to version 1.4.1.2, requests are handled by workers threads. Each sockets will be waited by the worker for at most 'ioblocktimeout' seconds. However this timeout applies only for un-encrypted requests. Connections using SSL/TLS are not taking this timeout into account during reads, and may hang longer.An unauthenticated attacker could repeatedly create hanging LDAP requests to hang all the workers, resulting in a Denial of Service.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2019-3883

больше 7 лет назад

In 389-ds-base up to version 1.4.1.2, requests are handled by workers threads. Each sockets will be waited by the worker for at most 'ioblocktimeout' seconds. However this timeout applies only for un-encrypted requests. Connections using SSL/TLS are not taking this timeout into account during reads, and may hang longer.An unauthenticated attacker could repeatedly create hanging LDAP requests to hang all the workers, resulting in a Denial of Service.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2019-3883

больше 7 лет назад

In 389-ds-base up to version 1.4.1.2, requests are handled by workers ...

CVSS3: 7.5
EPSS: Низкий
oracle-oval логотип

ELSA-2019-1896

около 7 лет назад

ELSA-2019-1896: 389-ds-base security and bug fix update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2019-3401

больше 6 лет назад

ELSA-2019-3401: 389-ds:1.4 security, bug fix, and enhancement update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:2155-1

почти 7 лет назад

Security update for 389-ds

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-c65q-p9xj-798w

In 389-ds-base up to version 1.4.1.2, requests are handled by workers threads. Each sockets will be waited by the worker for at most 'ioblocktimeout' seconds. However this timeout applies only for un-encrypted requests. Connections using SSL/TLS are not taking this timeout into account during reads, and may hang longer.An unauthenticated attacker could repeatedly create hanging LDAP requests to hang all the workers, resulting in a Denial of Service.

CVSS3: 7.5
8%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2019-3883

In 389-ds-base up to version 1.4.1.2, requests are handled by workers threads. Each sockets will be waited by the worker for at most 'ioblocktimeout' seconds. However this timeout applies only for un-encrypted requests. Connections using SSL/TLS are not taking this timeout into account during reads, and may hang longer.An unauthenticated attacker could repeatedly create hanging LDAP requests to hang all the workers, resulting in a Denial of Service.

CVSS3: 7.5
8%
Низкий
больше 7 лет назад
redhat логотип
CVE-2019-3883

In 389-ds-base up to version 1.4.1.2, requests are handled by workers threads. Each sockets will be waited by the worker for at most 'ioblocktimeout' seconds. However this timeout applies only for un-encrypted requests. Connections using SSL/TLS are not taking this timeout into account during reads, and may hang longer.An unauthenticated attacker could repeatedly create hanging LDAP requests to hang all the workers, resulting in a Denial of Service.

CVSS3: 5.3
8%
Низкий
больше 7 лет назад
nvd логотип
CVE-2019-3883

In 389-ds-base up to version 1.4.1.2, requests are handled by workers threads. Each sockets will be waited by the worker for at most 'ioblocktimeout' seconds. However this timeout applies only for un-encrypted requests. Connections using SSL/TLS are not taking this timeout into account during reads, and may hang longer.An unauthenticated attacker could repeatedly create hanging LDAP requests to hang all the workers, resulting in a Denial of Service.

CVSS3: 7.5
8%
Низкий
больше 7 лет назад
debian логотип
CVE-2019-3883

In 389-ds-base up to version 1.4.1.2, requests are handled by workers ...

CVSS3: 7.5
8%
Низкий
больше 7 лет назад
oracle-oval логотип
ELSA-2019-1896

ELSA-2019-1896: 389-ds-base security and bug fix update (MODERATE)

8%
Низкий
около 7 лет назад
oracle-oval логотип
ELSA-2019-3401

ELSA-2019-3401: 389-ds:1.4 security, bug fix, and enhancement update (IMPORTANT)

больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:2155-1

Security update for 389-ds

почти 7 лет назад

Уязвимостей на страницу