First published: Tue Apr 19 2016(Updated: )
slapd/connection.c in 389 Directory Server (formerly Fedora Directory Server) 1.3.4.x before 1.3.4.7 allows remote attackers to cause a denial of service (infinite loop and connection blocking) by leveraging an abnormally closed connection.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Enterprise Linux | =7.0 | |
Red Hat Enterprise Linux Desktop | =7.0 | |
Red Hat Enterprise Linux HPC Node | =7.0 | |
Red Hat Enterprise Linux Server | =7.0 | |
Red Hat Enterprise Linux Workstation | =7.0 | |
Red Hat 389 Directory Server | =1.3.4.0 | |
Red Hat 389 Directory Server | =1.3.4.1 | |
Red Hat 389 Directory Server | =1.3.4.4 | |
Red Hat 389 Directory Server | =1.3.4.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-0741 has a severity level that can result in denial of service due to an infinite loop and connection blocking.
To fix CVE-2016-0741, upgrade the 389 Directory Server to version 1.3.4.7 or later.
CVE-2016-0741 affects 389 Directory Server versions prior to 1.3.4.7 and specific Red Hat Enterprise Linux 7.0 variants.
CVE-2016-0741 enables remote attackers to conduct denial of service attacks by exploiting an improperly handled connection.
Yes, CVE-2016-0741 can significantly affect production environments by causing service unavailability.