CVE-2013-4485: Input Validation
389 Directory Server 1.2.11.15 (aka Red Hat Directory Server before 8.2.11-14) allows remote authenticated users to cause a denial of service (crash) via multiple @ characters in a GER attribute list in a search request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4485?
CVE-2013-4485 is classified as a denial of service vulnerability that can lead to a crash.
How do I fix CVE-2013-4485?
To mitigate CVE-2013-4485, update to the patched versions of Red Hat Directory Server as recommended in available advisories.
Who is affected by CVE-2013-4485?
CVE-2013-4485 impacts users of 389 Directory Server 1.2.11.15 and earlier versions on Red Hat Enterprise Linux 6.0 and other specified versions.
What type of attack does CVE-2013-4485 facilitate?
CVE-2013-4485 allows remote authenticated users to exploit the server by sending specially crafted requests containing multiple @ characters.
When was CVE-2013-4485 published?
CVE-2013-4485 was published in 2013, highlighting a significant vulnerability in certain Red Hat Directory Server versions.