First published: Thu Sep 05 2024(Updated: )
The fix for <a href="https://access.redhat.com/security/cve/CVE-2024-2199">CVE-2024-2199</a> in 389-ds-base was insufficient to cover all scenarios. in certain product versions, an authenticated user may cause a server crash while modifying `userPassword` using malformed input.
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Directory Server |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2310110 is significant as it allows an authenticated user to crash the server by modifying userPassword with malformed input.
To fix REDHAT-BUG-2310110, you should update your Red Hat 389-ds-base to the latest version that addresses the CVE-2024-2199.
REDHAT-BUG-2310110 can lead to a denial of service due to server crashes when processing malformed userPassword inputs.
REDHAT-BUG-2310110 affects specific versions of Red Hat 389-ds-base, particularly those prior to the security update for CVE-2024-2199.
Yes, a user must be authenticated to exploit REDHAT-BUG-2310110, which limits the risk to logged-in users.