rpm package
almalinux/389-ds-base-libs
pkg:rpm/almalinux/389-ds-base-libs
Vulnerabilities (22)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2022-0918 | Hig | 7.5 | < 1.4.3.28-7.module_el8.6.0+3071+d20b1d7c | 1.4.3.28-7.module_el8.6.0+3071+d20b1d7c | Mar 16, 2022 | A vulnerability was discovered in the 389 Directory Server that allows an unauthenticated attacker with network access to the LDAP port to cause a denial of service. The denial of service is triggered by a single message sent over a TCP connection, no bind or other authentication | |
| CVE-2021-4091 | Hig | 7.5 | < 1.4.3.23-14.module_el8.5.0+2628+c731dc97 | 1.4.3.23-14.module_el8.5.0+2628+c731dc97 | Feb 18, 2022 | A double-free was found in the way 389-ds-base handles virtual attributes context in persistent searches. An attacker could send a series of search requests, forcing the server to behave unexpectedly, and crash. |
- affected < 1.4.3.28-7.module_el8.6.0+3071+d20b1d7cfixed 1.4.3.28-7.module_el8.6.0+3071+d20b1d7c
A vulnerability was discovered in the 389 Directory Server that allows an unauthenticated attacker with network access to the LDAP port to cause a denial of service. The denial of service is triggered by a single message sent over a TCP connection, no bind or other authentication
- affected < 1.4.3.23-14.module_el8.5.0+2628+c731dc97fixed 1.4.3.23-14.module_el8.5.0+2628+c731dc97
A double-free was found in the way 389-ds-base handles virtual attributes context in persistent searches. An attacker could send a series of search requests, forcing the server to behave unexpectedly, and crash.
Page 2 of 2