REDHAT-BUG-1619450: Medium severity red hat directory server vulnerability
A flaw was found in 389-ds-base. The server can be crashed by an anonymous client through a ldapmodify command with a large DN argument potentially causing denial of service.
References:
https://bugzilla.redhat.com/showbug.cgi?id=1614820
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1619450?
The severity of REDHAT-BUG-1619450 is classified as a denial of service vulnerability.
How do I fix REDHAT-BUG-1619450?
To fix REDHAT-BUG-1619450, update to the latest version of the Red Hat 389-ds-base that addresses this vulnerability.
What causes REDHAT-BUG-1619450?
REDHAT-BUG-1619450 is caused by the server being able to be crashed by an anonymous client through an ldapmodify command with a large DN argument.
Who is affected by REDHAT-BUG-1619450?
Any installation of Red Hat 389-ds-base that allows anonymous connections is potentially affected by REDHAT-BUG-1619450.
Can an attacker exploit REDHAT-BUG-1619450 remotely?
Yes, an attacker can exploit REDHAT-BUG-1619450 remotely by sending a specially crafted ldapmodify command.