RHSA-2024:3591: Important: 389-ds-base security update
389 Directory Server is an LDAP version 3 (LDAPv3) compliant server. The base packages include the Lightweight Directory Access Protocol (LDAP) server and command-line utilities for server administration.<br>Security Fix(es):<br><li> 389-ds-base: potential denial of service via specially crafted kerberos AS-REQ request (CVE-2024-3657)</li> <li> 389-ds-base: Malformed userPassword may cause crash at domodify in slapd/modify.c (CVE-2024-2199)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:3591?
The severity of RHSA-2024:3591 is classified as a potential denial of service vulnerability.
How do I fix RHSA-2024:3591?
To fix RHSA-2024:3591, install the updated package version 1.3.11.1-5.el7_9 or later.
Which packages are affected by RHSA-2024:3591?
RHSA-2024:3591 affects packages such as 389-ds-base, 389-ds-base-devel, and 389-ds-base-libs.
What products are impacted by the RHSA-2024:3591 vulnerability?
The impacted products include Red Hat Enterprise Linux Server and Red Hat Enterprise Linux Desktop.
Is there a workaround for RHSA-2024:3591?
There is no known workaround for RHSA-2024:3591; updating to the patched version is recommended.