CVE-2013-0312: Medium severity fedoraproject 389 Directory Server vulnerability
389 Directory Server before 1.3.0.4 allows remote attackers to cause a denial of service (crash) via a zero length LDAP control sequence.
Other sources
It was discovered that an anonymous (or bound) LDAP request to the 389 Directory Server could trigger a crash of the server when handling LDAP V3 control data. If a malicious unauthenticated user were to send an LDAP request containing crafted LDAPv3 control data, they could cause the server to crash, denying service to the directory.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0312?
CVE-2013-0312 has a severity rating that indicates it can lead to a denial of service due to server crashes.
How do I fix CVE-2013-0312?
To fix CVE-2013-0312, you should update the 389 Directory Server to version 1.3.0.4 or later.
What systems are affected by CVE-2013-0312?
CVE-2013-0312 affects versions of 389 Directory Server prior to 1.3.0.4.
What kind of attack does CVE-2013-0312 facilitate?
CVE-2013-0312 facilitates a denial of service attack through a remote zero-length LDAP control sequence.
Can CVE-2013-0312 be exploited by anonymous users?
Yes, CVE-2013-0312 can be exploited by anonymous or bound users making LDAP requests.