First published: Fri Apr 23 2021(Updated: )
When using a sync_repl client in 389-ds-base, an authenticated attacker can cause a NULL pointer dereference using a specially crafted query, causing a crash.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat 389 Directory Server | ||
redhat/389-ds-base | <1.4.3.23 | 1.4.3.23 |
redhat/389-ds-base | <1.4.4.16 | 1.4.4.16 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2021-3514.
The Redhat 389 Directory Server is affected by this vulnerability.
The severity of CVE-2021-3514 is medium with a CVSS score of 6.5.
An authenticated attacker can exploit CVE-2021-3514 by causing a NULL pointer dereference using a specially crafted query.
Yes, you can find more information about CVE-2021-3514 in the following references: [Github](https://github.com/389ds/389-ds-base/issues/4711) and [Debian LTS Announcement](https://lists.debian.org/debian-lts-announce/2023/04/msg00026.html).