REDHAT-BUG-2310110: Medium severity red hat directory server vulnerability
The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios. in certain product versions, an authenticated user may cause a server crash while modifying userPassword using malformed input.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2310110?
The severity of REDHAT-BUG-2310110 is significant as it allows an authenticated user to crash the server by modifying userPassword with malformed input.
How do I fix REDHAT-BUG-2310110?
To fix REDHAT-BUG-2310110, you should update your Red Hat 389-ds-base to the latest version that addresses the CVE-2024-2199.
What impact does REDHAT-BUG-2310110 have on Red Hat 389-ds-base?
REDHAT-BUG-2310110 can lead to a denial of service due to server crashes when processing malformed userPassword inputs.
Which versions of Red Hat are affected by REDHAT-BUG-2310110?
REDHAT-BUG-2310110 affects specific versions of Red Hat 389-ds-base, particularly those prior to the security update for CVE-2024-2199.
Is authentication required to exploit REDHAT-BUG-2310110?
Yes, a user must be authenticated to exploit REDHAT-BUG-2310110, which limits the risk to logged-in users.