VYPR

rpm package

almalinux/389-ds-base-bdb

pkg:rpm/almalinux/389-ds-base-bdb

Vulnerabilities (3)

  • CVE-2026-11610HigJul 7, 2026
    affected < 3.2.0-8.el10_2fixed 3.2.0-8.el10_2

    A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). After a successful SASL bind with integrity protection (SSF > 0), an authenticated attacker can send a specially crafted oversized LDAP UNBIND packet that is copied into a 512-byte

  • CVE-2026-11774HigJun 11, 2026
    affected < 3.2.0-8.el10_2fixed 3.2.0-8.el10_2

    An integer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), adding sizeof(uint32_t) to a crafted SASL packet length prefix of 0xFFFFFFFC causes unsigned wraparound to zero, bypassing the nsslapd-maxsasliosize limit an

  • CVE-2025-14905HigFeb 23, 2026
    affected < 3.1.3-7.el10_1fixed 3.1.3-7.el10_1

    A flaw was found in the 389-ds-base server. A heap buffer overflow vulnerability exists in the `schema_attr_enum_callback` function within the `schema.c` file. This occurs because the code incorrectly calculates the buffer size by summing alias string lengths without accounting f