RHSA-2024:5192: Moderate: 389-ds-base security update
389 Directory Server is an LDAP version 3 (LDAPv3) compliant server. The base packages include the Lightweight Directory Access Protocol (LDAP) server and command-line utilities for server administration.Security Fix(es): 389-ds-base: Malformed userPassword hash may cause Denial of Service (CVE-2024-5953) 389-ds-base: unauthenticated user can trigger a DoS by sending a specific extended search request (CVE-2024-6237) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:5192?
The severity of RHSA-2024:5192 is categorized as critical due to potential exploitation risks.
How do I fix RHSA-2024:5192?
To fix RHSA-2024:5192, update to 389-ds-base version 2.4.5-9.el9_4 or later.
Which software is affected by RHSA-2024:5192?
RHSA-2024:5192 affects various versions of Red Hat Enterprise Linux Server and related products.
What type of vulnerability is addressed in RHSA-2024:5192?
RHSA-2024:5192 addresses vulnerabilities related to malformed userPassword hash processing.
Is there a workaround for RHSA-2024:5192?
Currently, no specific workaround for RHSA-2024:5192 is recommended, and applying the patch is advised.