RHSA-2024:4633HighCVSS 7.5
Red Hat Security Advisory: 389-ds-base security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2024-1062 — 389-ds-base: a heap overflow leading to denail-of-servce while writing a value larger than 256 chars (in log_entry_attr) CVE-2024-2199 — 389-ds-base: Malformed userPassword may cause crash at do_modify in slapd/modify.c CVE-2024-3657 — 389-ds-base: potential denial of service via specially crafted kerberos AS-REQ request CVE-2024-5953 — 389-ds-base: Malformed userPassword hash may cause Denial of Service
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2024:4633
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2261879
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2267976
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2274401
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2292104
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_4633.json