RHSA-2024:4633: Important: 389-ds-base security update
389 Directory Server is an LDAP version 3 (LDAPv3) compliant server. The base packages include the Lightweight Directory Access Protocol (LDAP) server and command-line utilities for server administration.Security Fix(es): 389-ds-base: a heap overflow leading to denail-of-servce while writing a value larger than 256 chars (in logentryattr) (CVE-2024-1062) 389-ds-base: Malformed userPassword may cause crash at domodify in slapd/modify.c (CVE-2024-2199) 389-ds-base: potential denial of service via specially crafted kerberos AS-REQ request (CVE-2024-3657) 389-ds-base: Malformed userPassword hash may cause Denial of Service (CVE-2024-5953) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:4633?
The severity of RHSA-2024:4633 is critical due to a heap overflow vulnerability that could lead to denial of service.
How do I fix RHSA-2024:4633?
To fix RHSA-2024:4633, update the affected packages to version 2.2.4-9.el9_2 or later.
Which packages are affected by RHSA-2024:4633?
The affected packages in RHSA-2024:4633 include 389-ds-base, 389-ds-base-libs, and related debuginfo packages.
What type of attack does RHSA-2024:4633 enable?
RHSA-2024:4633 enables attackers to potentially exploit a heap overflow, leading to service disruption.
Does RHSA-2024:4633 affect all users?
RHSA-2024:4633 primarily affects users running specific versions of 389 Directory Server on Red Hat Enterprise Linux.