VYPR

rpm package

opensuse/389-ds&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/389-ds&distro=openSUSE%20Tumbleweed

Vulnerabilities (49)

  • CVE-2026-19843HigSep 7, 2026
    affected < 3.3.1+8c2711bd6-1.1fixed 3.3.1+8c2711bd6-1.1

    A flaw was found in 389-ds-base. The Cockpit 389 Console's LDAP editor constructs an ldapsearch command by embedding an LDAP entry's distinguished name (DN) into a shell command string without proper escaping. An LDAP user with delegated privileges to create or rename directory e

  • CVE-2026-18922CriSep 7, 2026
    affected < 3.3.1+8c2711bd6-1.1fixed 3.3.1+8c2711bd6-1.1

    A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated successful bind, regardless of which SASL me

  • CVE-2026-18453HigSep 7, 2026
    affected < 3.3.1+8c2711bd6-1.1fixed 3.3.1+8c2711bd6-1.1

    A flaw was found in 389 Directory Server. A missing NULL pointer check in the paged results handling of op_shared_search allows an unauthenticated remote attacker to crash the LDAP server by sending a crafted sequence of search requests using the USE_ONE_BACKEND control, resultin

  • CVE-2026-18355HigSep 7, 2026
    affected < 3.3.1+8c2711bd6-1.1fixed 3.3.1+8c2711bd6-1.1

    A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), the wrapped-record length read from the wire is validated only against an upper bound. A small wire length (0, 1, or 2) produces an encrypted_buffer_count

  • CVE-2026-76560HigSep 7, 2026
    affected < 3.3.1+8c2711bd6-1.1fixed 3.3.1+8c2711bd6-1.1

    A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule evaluator incorrectly matches an anonymous LDAP client's empty bind DN against an empty stored attribute value, allowing an unauthenticated client to satisfy access control checks intended to require a matching au

  • CVE-2026-18663MedAug 12, 2026
    affected < 3.3.1+8c2711bd6-1.1fixed 3.3.1+8c2711bd6-1.1

    A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function frees the parsed controls array on the Session Tracking critical-control rejection path without clearing the SLAPI_REQCONTROLS pblock slot. Operation teardown then frees the same pointer again, causing a

  • CVE-2026-15722HigJul 31, 2026
    affected < 3.3.1+8c2711bd6-1.1fixed 3.3.1+8c2711bd6-1.1

    A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds checking. A remote unauthenticated at

  • CVE-2026-11770HigJul 31, 2026
    affected < 3.3.1+8c2711bd6-1.1fixed 3.3.1+8c2711bd6-1.1

    A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated replication plugin privileges and

  • CVE-2026-11610HigJul 7, 2026
    affected < 3.2.2+4b41542b2-1.1fixed 3.2.2+4b41542b2-1.1

    A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). After a successful SASL bind with integrity protection (SSF > 0), an authenticated attacker can send a specially crafted oversized LDAP UNBIND packet that is copied into a 512-byte

  • CVE-2026-11791MedJun 18, 2026
    affected < 3.2.2+4b41542b2-1.1fixed 3.2.2+4b41542b2-1.1

    A flaw was found in 389 Directory Server. During schema reload, the attr_syntax_swap_ht() function unconditionally frees attribute syntax information nodes, bypassing the refcount-based deferred deletion used elsewhere in the attribute syntax subsystem. If an administrator trigge

  • CVE-2026-12528MedJun 17, 2026
    affected < 3.2.2+4b41542b2-1.1fixed 3.2.2+4b41542b2-1.1

    A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c. A malformed ACI (Access Control Instruction) string can trigger heap-buffer-overflow writes and reads during ACI parsing. The function fails to validate that the ACI keyword has suf

  • CVE-2026-11774HigJun 11, 2026
    affected < 3.2.2+4b41542b2-1.1fixed 3.2.2+4b41542b2-1.1

    An integer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), adding sizeof(uint32_t) to a crafted SASL packet length prefix of 0xFFFFFFFC causes unsigned wraparound to zero, bypassing the nsslapd-maxsasliosize limit an

  • CVE-2026-11884MedJun 10, 2026
    affected < 3.2.2+4b41542b2-1.1fixed 3.2.2+4b41542b2-1.1

    A heap buffer overflow flaw was found in 389 Directory Server. When serializing objectclass definitions, the oc_superior (SUP) field length is omitted from buffer size calculations in read_schema_dse() and schema_oc_to_string(), but the field is still written via strcat(). An att

  • CVE-2026-11793MedJun 9, 2026
    affected < 3.2.2+4b41542b2-1.1fixed 3.2.2+4b41542b2-1.1

    A stack buffer overflow flaw was found in 389 Directory Server. The checkPrefix() function in pw.c copies an attacker-controlled algorithm ID into a 256-byte stack buffer without bounds checking when parsing reversible-encrypted attribute values. An attacker with Directory Manage

  • CVE-2026-11792LowJun 9, 2026
    affected < 3.2.2+4b41542b2-1.1fixed 3.2.2+4b41542b2-1.1

    A heap buffer overflow flaw was found in 389 Directory Server. When audit logging is enabled, the create_masked_entry_string() function in auditlog.c copies a fixed-length password mask into a precisely-sized heap buffer without checking available space. If a short cleartext pass

  • CVE-2026-11790MedJun 9, 2026
    affected < 3.2.2+4b41542b2-1.1fixed 3.2.2+4b41542b2-1.1

    A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password storage plugin does not enforce an upper bound on the iteration count extracted from stored password hashes. A privileged attacker who can modify a user's password hash can cause excessive CPU consumption during

  • CVE-2026-11789MedJun 9, 2026
    affected < 3.2.2+4b41542b2-1.1fixed 3.2.2+4b41542b2-1.1

    A flaw was found in 389 Directory Server. The SMD5 password storage plugin performs unsigned integer underflow when computing salt length from a crafted password hash shorter than 16 bytes, causing a buffer over-read that crashes the LDAP server during authentication.

  • CVE-2026-11788MedJun 9, 2026
    affected < 3.2.2+4b41542b2-1.1fixed 3.2.2+4b41542b2-1.1

    A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing an unauthenticated remote attacker to crash the LDAP server when the system is under memory pressure.

  • CVE-2026-11787MedJun 9, 2026
    affected < 3.2.2+4b41542b2-1.1fixed 3.2.2+4b41542b2-1.1

    A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffer without bounds checking, causing a heap buffer over-read in string filter parsing that may influence internal filter processing behavior.

  • CVE-2026-11786LowJun 9, 2026
    affected < 3.2.2+4b41542b2-1.1fixed 3.2.2+4b41542b2-1.1

    A flaw was found in 389 Directory Server. The LDIF parser reads past the end of a heap buffer when processing attribute types with trailing semicolons during database import, causing an out-of-bounds read detectable under memory instrumentation.

Page 1 of 3