CVE-2018-1089: Buffer Overflow
389-ds-base before versions 1.4.0.9, 1.3.8.1, 1.3.6.15 did not properly handle long search filters with characters needing escapes, possibly leading to buffer overflows. A remote, unauthenticated attacker could potentially use this flaw to make ns-slapd crash via a specially crafted LDAP request, thus resulting in denial of service.
Other sources
It is possible to crash ns-slapd (and ipa-dnskeysyncd afterwards) with crafted ldapsearch query with very long filter value both as anonymous or authenticated user. The crash can be similarly triggered with a query via the FreeIPA API as an authenticated user.
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-1089?
CVE-2018-1089 is a vulnerability in 389-ds-base versions 1.4.0.9, 1.3.8.1, and 1.3.6.15 that could lead to buffer overflows.
How does CVE-2018-1089 impact 389-ds-base?
CVE-2018-1089 could allow a remote, unauthenticated attacker to crash the ns-slapd service by sending a specially crafted LDAP request.
What is the severity of CVE-2018-1089?
CVE-2018-1089 has a severity rating of 7.5 (high).
How can I fix CVE-2018-1089?
To fix CVE-2018-1089, update 389-ds-base to version 1.4.0.9, 1.3.8.1, or 1.3.6.15 depending on your installed version.
Where can I find more information about CVE-2018-1089?
You can find more information about CVE-2018-1089 at the following references: [SecurityFocus](http://www.securityfocus.com/bid/104137), [Red Hat Security Advisory RHSA-2018:1364](https://access.redhat.com/errata/RHSA-2018:1364), [Red Hat Security Advisory RHSA-2018:1380](https://access.redhat.com/errata/RHSA-2018:1380).