CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:N/I:N/A:P
AI Score
Confidence
Low
EPSS
Percentile
85.2%
Multiple memory leaks in the normalization functionality in 389 Directory Server before 1.2.7.5 allow remote attackers to cause a denial of service (memory consumption) via “badly behaved applications,” related to (1) Slapi_Attr mishandling in the DN normalization code and (2) pointer mishandling in the syntax normalization code, a different issue than CVE-2011-0019.
Vendor | Product | Version | CPE |
---|---|---|---|
fedoraproject | 389_directory_server | * | cpe:2.3:a:fedoraproject:389_directory_server:*:alpha3:*:*:*:*:*:* |
fedoraproject | 389_directory_server | 1.2.1 | cpe:2.3:a:fedoraproject:389_directory_server:1.2.1:*:*:*:*:*:*:* |
fedoraproject | 389_directory_server | 1.2.2 | cpe:2.3:a:fedoraproject:389_directory_server:1.2.2:*:*:*:*:*:*:* |
fedoraproject | 389_directory_server | 1.2.3 | cpe:2.3:a:fedoraproject:389_directory_server:1.2.3:*:*:*:*:*:*:* |
fedoraproject | 389_directory_server | 1.2.5 | cpe:2.3:a:fedoraproject:389_directory_server:1.2.5:*:*:*:*:*:*:* |
fedoraproject | 389_directory_server | 1.2.5 | cpe:2.3:a:fedoraproject:389_directory_server:1.2.5:rc1:*:*:*:*:*:* |
fedoraproject | 389_directory_server | 1.2.5 | cpe:2.3:a:fedoraproject:389_directory_server:1.2.5:rc2:*:*:*:*:*:* |
fedoraproject | 389_directory_server | 1.2.5 | cpe:2.3:a:fedoraproject:389_directory_server:1.2.5:rc3:*:*:*:*:*:* |
fedoraproject | 389_directory_server | 1.2.5 | cpe:2.3:a:fedoraproject:389_directory_server:1.2.5:rc4:*:*:*:*:*:* |
fedoraproject | 389_directory_server | 1.2.6 | cpe:2.3:a:fedoraproject:389_directory_server:1.2.6:*:*:*:*:*:*:* |