CVE-2018-1054: High severity red hat 389 directory server vulnerability
A flaw was found in 389 Directory Server, affecting all versions including upstream 1.4.x. An improper handling of the search feature with an extended filter, when read access on <attributename> is enabled, in SetUnicodeStringFromUTF8 function in collate.c, can lead to out-of-bounds memory operations. This may allow a remote unauthenticated attacker to trigger a server crash, thus resulting in denial of service.
External References:
https://pagure.io/389-ds-base/issue/49545
Upstream Patch:
https://pagure.io/389-ds-base/c/14ce2fe0dfa67405dae
Other sources
An out-of-bounds memory read flaw was found in the way 389-ds-base handled certain LDAP search filters, affecting all versions including 1.4.x. A remote, unauthenticated attacker could potentially use this flaw to make ns-slapd crash via a specially crafted LDAP request, thus resulting in denial of service.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this out-of-bounds memory read flaw?
The vulnerability ID for this flaw is CVE-2018-1054.
How does the out-of-bounds memory read flaw affect 389-ds-base?
The out-of-bounds memory read flaw affects all versions of 389-ds-base including 1.4.x.
What is the severity rating of CVE-2018-1054?
CVE-2018-1054 has a severity rating of 7.5 out of 10.
Which software versions are affected by CVE-2018-1054?
CVE-2018-1054 affects versions 1.3.6.14 up to 1.4.0.6 of 389-ds-base.
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by sending a specially crafted LDAP request, causing ns-slapd to crash.