CVE-2018-14624: Input Validation
A flaw was found in 389-ds-base. The server can be crashed by an anonymous client through a ldapmodify command with a large DN argument potentially causing denial of service.
References:
https://bugzilla.redhat.com/showbug.cgi?id=1614820
Other sources
A vulnerability was discovered in 389-ds-base through versions 1.3.7.10, 1.3.8.8 and 1.4.0.16. The lock controlling the error log was not correctly used when re-opening the log file in logerroremergency(). An attacker could send a flood of modifications to a very large DN, which would cause slapd to crash.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-14624?
CVE-2018-14624 has a medium severity rating due to the potential for denial of service attacks.
How do I fix CVE-2018-14624?
To fix CVE-2018-14624, upgrade to 389-ds-base versions 1.3.7.11, 1.3.8.9, or 1.4.0.17 and apply all necessary patches.
What impact does CVE-2018-14624 have on Red Hat 389 Directory Server?
CVE-2018-14624 allows an attacker to flood error logs under specific conditions, possibly leading to service disruption.
Can CVE-2018-14624 affect other operating systems?
Yes, CVE-2018-14624 can affect various Linux distributions that utilize vulnerable versions of the 389 Directory Server.
Is there a workaround for CVE-2018-14624?
There are no recommended workarounds for CVE-2018-14624; patching to the secure version is the best approach.