RHSA-2024:3837: Important: 389-ds-base security update
389 Directory Server is an LDAP version 3 (LDAPv3) compliant server. The basepackages include the Lightweight Directory Access Protocol (LDAP) server andcommand-line utilities for server administration.Security Fix(es): 389-ds-base: potential denial of service via specially crafted kerberos AS-REQ request (CVE-2024-3657) 389-ds-base: Malformed userPassword may cause crash at domodify in slapd/modify.c (CVE-2024-2199) For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:3837?
RHSA-2024:3837 is classified as an important security update.
How do I fix RHSA-2024:3837?
To remedy RHSA-2024:3837, upgrade the affected package to version 2.4.5-8.el9_4.
Which products are affected by RHSA-2024:3837?
RHSA-2024:3837 affects various Red Hat Enterprise Linux products including for x86_64 and IBM z Systems.
What is the main purpose of the update in RHSA-2024:3837?
The update in RHSA-2024:3837 aims to address security vulnerabilities in the 389-ds-base package.
How can I verify if my system is affected by RHSA-2024:3837?
You can verify if your system is affected by checking the installed version of the 389-ds-base package against the advisory.