CVE-2021-3514: Null Pointer Dereference
When using a syncrepl client in 389-ds-base, an authenticated attacker can cause a NULL pointer dereference using a specially crafted query, causing a crash.
Other sources
When using a syncrepl client, an authenticated attacker can cause a NULL pointer dereference using a specially crafted query, causing a crash of 389-ds-base.
Upstream reference: https://github.com/389ds/389-ds-base/issues/4711
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/389-ds-baseto a version that resolves this vulnerability.Fixed in 1.4.3.23 - Upgrade
Upgrade
redhat/389-ds-baseto a version that resolves this vulnerability.Fixed in 1.4.4.16
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-3514.
What software is affected by this vulnerability?
The Redhat 389 Directory Server is affected by this vulnerability.
What is the severity of CVE-2021-3514?
The severity of CVE-2021-3514 is medium with a CVSS score of 6.5.
How can an authenticated attacker exploit CVE-2021-3514?
An authenticated attacker can exploit CVE-2021-3514 by causing a NULL pointer dereference using a specially crafted query.
Are there any references or resources for CVE-2021-3514?
Yes, you can find more information about CVE-2021-3514 in the following references: [Github](https://github.com/389ds/389-ds-base/issues/4711) and [Debian LTS Announcement](https://lists.debian.org/debian-lts-announce/2023/04/msg00026.html).