CVE-2018-14638: Double Free
A flaw was found in 389-ds-base before version 1.3.8.4-13. The process ns-slapd crashes in deletepasswdPolicy function when persistent search connections are terminated unexpectedly leading to remote denial of service.
Other sources
A flaw was found in 389-ds-base. The process ns-slapd crashes in deletepasswdPolicy function when persistent search connections are terminated unexpectedly leading to remote denial of service.
References:
https://bugzilla.redhat.com/showbug.cgi?id=1623949
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2018-14638.
What is the severity of CVE-2018-14638?
The severity of CVE-2018-14638 is high (7.5).
What is the affected software?
The affected software includes 389-ds-base before version 1.3.8.4-13 on Red Hat Enterprise Linux and Fedora Directory Server.
How does CVE-2018-14638 impact the system?
CVE-2018-14638 can lead to remote denial of service when persistent search connections are terminated unexpectedly.
How can CVE-2018-14638 be fixed?
CVE-2018-14638 can be fixed by updating to version 1.4.0.17 of 389-ds-base.