Lucene search

K
cvelistRedhatCVELIST:CVE-2021-4091
HistoryFeb 18, 2022 - 12:00 a.m.

CVE-2021-4091

2022-02-1800:00:00
CWE-415
redhat
www.cve.org
7
389-ds-base
double-free vulnerability
virtual attributes
persistent searches
server crashes

EPSS

0.001

Percentile

37.1%

A double-free was found in the way 389-ds-base handles virtual attributes context in persistent searches. An attacker could send a series of search requests, forcing the server to behave unexpectedly, and crash.

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "389-ds-base",
    "versions": [
      {
        "version": "389-ds-base-1.3.10.2",
        "status": "affected"
      }
    ]
  }
]