CVE-2013-4283: Input Validation
Published Aug 21, 2013
·Updated
ns-slapd in 389 Directory Server before 1.3.0.8 allows remote attackers to cause a denial of service (server crash) via a crafted Distinguished Name (DN) in a MOD operation request.
Affected Software
6 affected components
Fedoraproject 389 Directory Server<=1.3.0.7
Fedoraproject 389 Directory Server=1.3.0.2
Fedoraproject 389 Directory Server=1.3.0.3
Fedoraproject 389 Directory Server=1.3.0.4
Fedoraproject 389 Directory Server=1.3.0.5
Fedoraproject 389 Directory Server=1.3.0.6
Remediation
Patch Available
Event History
Aug 21, 2013
Data Sourced
06:16 PM
DescriptionSeverityAffected Software
Sep 10, 2013
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-4283?
CVE-2013-4283 has a severity rating that indicates it can lead to a denial of service condition.
2
How do I fix CVE-2013-4283?
To fix CVE-2013-4283, update the 389 Directory Server to version 1.3.0.8 or later.
3
Who is affected by CVE-2013-4283?
CVE-2013-4283 affects users of 389 Directory Server versions before 1.3.0.8.
4
What type of attack does CVE-2013-4283 enable?
CVE-2013-4283 enables remote attackers to cause a crash of the server through crafted input.
5
Is CVE-2013-4283 exploitative in nature?
Yes, CVE-2013-4283 is exploitative as it can be triggered by sending specially crafted requests to the server.