Lucene search

K
osvGoogleOSV:SUSE-SU-2024:3218-1
HistorySep 12, 2024 - 11:16 a.m.

Security update for 389-ds

2024-09-1211:16:05
Google
osv.dev
389-ds
security update
dos
heap overflow
vulnerabilities

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.4

Confidence

High

This update for 389-ds fixes the following issues:

  • Update to version 2.0.20
  • CVE-2024-3657: DOS via via specially crafted kerberos AS-REQ request. (bsc#1225512)
  • CVE-2024-5953: Malformed userPassword hashes may cause a denial of service. (bsc#1226277)
  • CVE-2024-2199: Malformed userPassword may cause crash at do_modify in slapd/modify.c. (bsc#1225507)
  • CVE-2024-1062: Fixed a heap overflow leading to denail-of-servce while writing a value larger than 256 chars in log_entry_attr. (bsc#1219836)

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.4

Confidence

High