First published: Wed Aug 08 2018(Updated: )
A flaw was found in the 389 Directory Server that allows users to cause a crash in the LDAP server using ldapsearch with server side sort.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat 389 Directory Server | >=1.3.0.0<1.3.8.7 | |
Redhat 389 Directory Server | >=1.4.0.0<1.4.0.14 | |
redhat/389-ds-base | <1.3.8.7 | 1.3.8.7 |
redhat/389-ds-base | <1.4.0.14 | 1.4.0.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-10935 is a vulnerability in the 389 Directory Server that allows users to cause a crash in the LDAP server using ldapsearch with server-side sort.
CVE-2018-10935 affects versions 1.3.0.0 up to, but excluding, 1.3.8.7 and versions 1.4.0.0 up to, but excluding, 1.4.0.14 of 389 Directory Server.
CVE-2018-10935 has a severity score of 6.5 (medium).
To fix CVE-2018-10935, update your 389 Directory Server to version 1.3.8.7 or higher if you are using version 1.3.x, or update to version 1.4.0.14 or higher if you are using version 1.4.x.
You can find more information about CVE-2018-10935 in the following references: [bugzilla.redhat.com/show_bug.cgi?id=1607078](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1607078), [bugzilla.redhat.com/show_bug.cgi?id=1613607](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1613607), [pagure.io/389-ds-base/issue/49890](https://pagure.io/389-ds-base/issue/49890).