First published: Thu Sep 05 2024(Updated: )
The fix for <a href="https://access.redhat.com/security/cve/CVE-2024-2199">CVE-2024-2199</a> in 389-ds-base was insufficient to cover all scenarios. in certain product versions, an authenticated user may cause a server crash while modifying `userPassword` using malformed input.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Directory Server |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-8445 is classified as a medium severity vulnerability due to the potential for server crashes under specific conditions.
To mitigate CVE-2024-8445, update to the latest version of 389-ds-base that includes the necessary patches.
CVE-2024-8445 impacts certain versions of Red Hat 389-ds-base where malformed input can cause server crashes.
CVE-2024-8445 is caused by an insufficient fix for CVE-2024-2199, allowing authenticated users to exploit malformed inputs.
CVE-2024-8445 requires authenticated access, thus it cannot be exploited remotely by unauthenticated users.