CVE-2018-10935: Input Validation
389 Directory Server has a flaw that allows users to cause a crash in the LDAP server using ldapsearch with server side sort.
Product Bug:
https://bugzilla.redhat.com/showbug.cgi?id=1607078
Other sources
A flaw was found in the 389 Directory Server that allows users to cause a crash in the LDAP server using ldapsearch with server side sort.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-10935?
CVE-2018-10935 is a vulnerability in the 389 Directory Server that allows users to cause a crash in the LDAP server using ldapsearch with server-side sort.
How does CVE-2018-10935 affect 389 Directory Server?
CVE-2018-10935 affects versions 1.3.0.0 up to, but excluding, 1.3.8.7 and versions 1.4.0.0 up to, but excluding, 1.4.0.14 of 389 Directory Server.
What is the severity of CVE-2018-10935?
CVE-2018-10935 has a severity score of 6.5 (medium).
How can I fix CVE-2018-10935?
To fix CVE-2018-10935, update your 389 Directory Server to version 1.3.8.7 or higher if you are using version 1.3.x, or update to version 1.4.0.14 or higher if you are using version 1.4.x.
Where can I find more information about CVE-2018-10935?
You can find more information about CVE-2018-10935 in the following references: [bugzilla.redhat.com/show_bug.cgi?id=1607078](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1607078), [bugzilla.redhat.com/show_bug.cgi?id=1613607](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1613607), [pagure.io/389-ds-base/issue/49890](https://pagure.io/389-ds-base/issue/49890).