First published: Wed Feb 20 2013(Updated: )
389 Directory Server before 1.3.0.4 allows remote attackers to cause a denial of service (crash) via a zero length LDAP control sequence.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/389-ds-base | <1.3.0.4 | 1.3.0.4 |
Red Hat 389 Directory Server | <=1.3.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-0312 has a severity rating that indicates it can lead to a denial of service due to server crashes.
To fix CVE-2013-0312, you should update the 389 Directory Server to version 1.3.0.4 or later.
CVE-2013-0312 affects versions of 389 Directory Server prior to 1.3.0.4.
CVE-2013-0312 facilitates a denial of service attack through a remote zero-length LDAP control sequence.
Yes, CVE-2013-0312 can be exploited by anonymous or bound users making LDAP requests.