Количество 11
Количество 11
CVE-2026-11793
A stack buffer overflow flaw was found in 389 Directory Server. The checkPrefix() function in pw.c copies an attacker-controlled algorithm ID into a 256-byte stack buffer without bounds checking when parsing reversible-encrypted attribute values. An attacker with Directory Manager privileges can crash the LDAP server by storing a crafted credential with an oversized algorithm ID. FORTIFY_SOURCE mitigates this to denial of service only.
CVE-2026-11793
A stack buffer overflow flaw was found in 389 Directory Server. The checkPrefix() function in pw.c copies an attacker-controlled algorithm ID into a 256-byte stack buffer without bounds checking when parsing reversible-encrypted attribute values. An attacker with Directory Manager privileges can crash the LDAP server by storing a crafted credential with an oversized algorithm ID. FORTIFY_SOURCE mitigates this to denial of service only.
CVE-2026-11793
A stack buffer overflow flaw was found in 389 Directory Server. The checkPrefix() function in pw.c copies an attacker-controlled algorithm ID into a 256-byte stack buffer without bounds checking when parsing reversible-encrypted attribute values. An attacker with Directory Manager privileges can crash the LDAP server by storing a crafted credential with an oversized algorithm ID. FORTIFY_SOURCE mitigates this to denial of service only.
CVE-2026-11793
A stack buffer overflow flaw was found in 389 Directory Server. The ch ...
ROS-20260922-80-0134
Уязвимость 389-ds-base
ROS-20260922-73-0104
Уязвимость 389-ds-base
GHSA-v6v5-66j3-444p
A stack buffer overflow flaw was found in 389 Directory Server. The checkPrefix() function in pw.c copies an attacker-controlled algorithm ID into a 256-byte stack buffer without bounds checking when parsing reversible-encrypted attribute values. An attacker with Directory Manager privileges can crash the LDAP server by storing a crafted credential with an oversized algorithm ID. FORTIFY_SOURCE mitigates this to denial of service only.
openSUSE-SU-2026:21691-1
Security update for 389-ds
SUSE-SU-2026:3138-1
Security update for 389-ds
SUSE-SU-2026:3137-1
Security update for 389-ds
SUSE-SU-2026:3136-1
Security update for 389-ds
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-11793 A stack buffer overflow flaw was found in 389 Directory Server. The checkPrefix() function in pw.c copies an attacker-controlled algorithm ID into a 256-byte stack buffer without bounds checking when parsing reversible-encrypted attribute values. An attacker with Directory Manager privileges can crash the LDAP server by storing a crafted credential with an oversized algorithm ID. FORTIFY_SOURCE mitigates this to denial of service only. | CVSS3: 4.9 | 0% Низкий | 4 месяца назад | |
CVE-2026-11793 A stack buffer overflow flaw was found in 389 Directory Server. The checkPrefix() function in pw.c copies an attacker-controlled algorithm ID into a 256-byte stack buffer without bounds checking when parsing reversible-encrypted attribute values. An attacker with Directory Manager privileges can crash the LDAP server by storing a crafted credential with an oversized algorithm ID. FORTIFY_SOURCE mitigates this to denial of service only. | CVSS3: 4.9 | 0% Низкий | 5 месяцев назад | |
CVE-2026-11793 A stack buffer overflow flaw was found in 389 Directory Server. The checkPrefix() function in pw.c copies an attacker-controlled algorithm ID into a 256-byte stack buffer without bounds checking when parsing reversible-encrypted attribute values. An attacker with Directory Manager privileges can crash the LDAP server by storing a crafted credential with an oversized algorithm ID. FORTIFY_SOURCE mitigates this to denial of service only. | CVSS3: 4.9 | 0% Низкий | 4 месяца назад | |
CVE-2026-11793 A stack buffer overflow flaw was found in 389 Directory Server. The ch ... | CVSS3: 4.9 | 0% Низкий | 4 месяца назад | |
ROS-20260922-80-0134 Уязвимость 389-ds-base | CVSS3: 4.9 | 0% Низкий | 3 дня назад | |
ROS-20260922-73-0104 Уязвимость 389-ds-base | CVSS3: 4.9 | 0% Низкий | 3 дня назад | |
GHSA-v6v5-66j3-444p A stack buffer overflow flaw was found in 389 Directory Server. The checkPrefix() function in pw.c copies an attacker-controlled algorithm ID into a 256-byte stack buffer without bounds checking when parsing reversible-encrypted attribute values. An attacker with Directory Manager privileges can crash the LDAP server by storing a crafted credential with an oversized algorithm ID. FORTIFY_SOURCE mitigates this to denial of service only. | CVSS3: 4.9 | 0% Низкий | 4 месяца назад | |
openSUSE-SU-2026:21691-1 Security update for 389-ds | 25 дней назад | |||
SUSE-SU-2026:3138-1 Security update for 389-ds | 2 месяца назад | |||
SUSE-SU-2026:3137-1 Security update for 389-ds | 2 месяца назад | |||
SUSE-SU-2026:3136-1 Security update for 389-ds | 2 месяца назад |
Уязвимостей на страницу