CVE-2024-1062: 389-ds-base: a heap overflow leading to denail-of-servce while writing a value larger than 256 chars (in log_entry_attr)
A heap overflow flaw was found in 389-ds-base. This issue leads to a denial of service when writing a value larger than 256 chars in logentryattr.
Other sources
A heap overflow problem was found in RHDS leading to denail-of-servce while writing a value larger than 256 chars (in logentryattr)
Refer: https://bugzilla.redhat.com/showbug.cgi?id=2256711
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/389-ds-baseto a version that resolves this vulnerability.Fixed in 2.2.0
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1062?
CVE-2024-1062 is classified as a high severity vulnerability due to its potential to cause a denial of service.
How do I fix CVE-2024-1062?
To fix CVE-2024-1062, update the affected version of 389-ds-base to at least version 2.2.0 or later.
What systems are affected by CVE-2024-1062?
CVE-2024-1062 affects versions of 389-ds-base up to 2.2.0 and several versions of Red Hat Directory Server.
What type of vulnerability is CVE-2024-1062?
CVE-2024-1062 is a heap overflow vulnerability that occurs when writing values larger than 256 characters in log_entry_attr.
What are the potential impacts of CVE-2024-1062?
The potential impacts of CVE-2024-1062 include service disruption and denial of service due to the heap overflow.