Lucene search

K
ubuntucveUbuntu.comUB:CVE-2017-2591
HistoryApr 30, 2018 - 12:00 a.m.

CVE-2017-2591

2018-04-3000:00:00
ubuntu.com
ubuntu.com
12

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.002

Percentile

59.1%

389-ds-base before version 1.3.6 is vulnerable to an improperly NULL
terminated array in the uniqueness_entry_to_config() function in the
“attribute uniqueness” plugin of 389 Directory Server. An authenticated, or
possibly unauthenticated, attacker could use this flaw to force an
out-of-bound heap memory read, possibly triggering a crash of the LDAP
service.

Bugs

Notes

Author Note
leosilva the project changed its site. That’s the current one: https://pagure.io/389-ds-base for commits from the older site, just copy the sha and paste with /c/<sha-commit>
OSVersionArchitecturePackageVersionFilename
ubuntu16.04noarch389-ds-base< anyUNKNOWN

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.002

Percentile

59.1%