RHSA-2024:1372: Moderate: redhat-ds:11 security, bug fix, and enhancement update
Moderate: redhat-ds:11 security, bug fix, and enhancement update
Other sources
Red Hat Directory Server is an LDAPv3-compliant directory server. The suite of packages includes the Lightweight Directory Access Protocol (LDAP) server, as well as command-line utilities and Web UI packages for server administration.<br>Security Fix(es):<br><li> 389-ds-base: A heap overflow flaw that leads to a denial of service when writing a value larger than 256 chars in logentryattr. (CVE-2024-1062)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Bug Fix(es) and Enhancement(s):<br><li> Adequate etime and no error "Retry count exceeded" on bind, add, delete, and modify operations from revertcache (BZ#2268136)</li> <li> RHDS LDAP server segmentation works as expected (BZ#2268138)</li> <li> Slow search when using filter with a virtual attribute (eg: nsRole ). (BZ#2265536)</li> <li> RHDS healthcheck incorrectly complains about missing backend definitions. (BZ#2265537)</li> <li> Paged search impacts performance (BZ#2265544)</li> <li> dtablesize being set to soft maxfiledescriptor limit causing massive slowdown in large environments (BZ#2265538)</li> <li> dsconf should prevent setting the replicaID for hub and consumer roles. (BZ#2265543)</li> <li> bdbstart - Detected Disorderly Shutdown directory server is not starting (BZ#2265540)</li> <li> After an upgrade the LDAP server wont start if nsslapd-conntablesize is present in the dse.ldif file (BZ#2265539)</li> <li> [RFE] Required to support both at a same time account inactivity and expiration. (BZ#2265541)</li>
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:1372?
The severity of RHSA-2024:1372 is classified as moderate.
How do I fix RHSA-2024:1372?
To fix RHSA-2024:1372, update the affected packages to version 1.4.3.34-3.module+el8d or later.
Which products are affected by RHSA-2024:1372?
RHSA-2024:1372 affects Red Hat Directory Server and several associated packages including 389-ds-base.
What types of updates are included in RHSA-2024:1372?
RHSA-2024:1372 includes security, bug fix, and enhancement updates.
Is there a recommended action for users of Red Hat Directory Server concerning RHSA-2024:1372?
Users of Red Hat Directory Server should apply the updates as soon as possible to mitigate potential vulnerabilities.