CVE-2008-3283
published 2008-08-29CVE-2008-3283: Multiple memory leaks in Red Hat Directory Server 7.1 before SP7, Red Hat Directory Server 8, and Fedora Directory Server 1.1.1 and earlier allow remote…
PriorityP432high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
2.85%
85.1th percentile
Multiple memory leaks in Red Hat Directory Server 7.1 before SP7, Red Hat Directory Server 8, and Fedora Directory Server 1.1.1 and earlier allow remote attackers to cause a denial of service (memory consumption) via vectors involving (1) the authentication / bind phase and (2) anonymous LDAP search requests.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedora | directory_server | — | — |
| redhat | directory_server | — | — |
| redhat | directory_server | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vxv8-22w3-3cgm: Multiple memory leaks in Red Hat Directory Server 7
ghsa_unreviewed·2022-05-01
CVE-2008-3283 [HIGH] GHSA-vxv8-22w3-3cgm: Multiple memory leaks in Red Hat Directory Server 7
Multiple memory leaks in Red Hat Directory Server 7.1 before SP7, Red Hat Directory Server 8, and Fedora Directory Server 1.1.1 and earlier allow remote attackers to cause a denial of service (memory consumption) via vectors involving (1) the authentication / bind phase and (2) anonymous LDAP search requests.
Red Hat
Server: multiple memory leaks
vendor_redhat·2008-08-27·CVSS 7.8
CVE-2008-3283 [HIGH] CWE-401 Server: multiple memory leaks
Server: multiple memory leaks
Multiple memory leaks in Red Hat Directory Server 7.1 before SP7, Red Hat Directory Server 8, and Fedora Directory Server 1.1.1 and earlier allow remote attackers to cause a denial of service (memory consumption) via vectors involving (1) the authentication / bind phase and (2) anonymous LDAP search requests.
No detection rules found.
No public exploits indexed.
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01532861http://secunia.com/advisories/31565http://secunia.com/advisories/31627http://secunia.com/advisories/31702http://secunia.com/advisories/31867http://secunia.com/advisories/31913http://securitytracker.com/id?1020774http://www.redhat.com/docs/manuals/dir-server/release-notes/7.1SP7/index.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0602.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0858.htmlhttp://www.securityfocus.com/bid/30872http://www.vupen.com/english/advisories/2008/2480https://bugzilla.redhat.com/show_bug.cgi?id=458977https://exchange.xforce.ibmcloud.com/vulnerabilities/44731https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6118https://rhn.redhat.com/errata/RHSA-2008-0596.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-September/msg00521.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-September/msg00708.htmlhttp://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01532861http://secunia.com/advisories/31565http://secunia.com/advisories/31627http://secunia.com/advisories/31702http://secunia.com/advisories/31867http://secunia.com/advisories/31913http://securitytracker.com/id?1020774http://www.redhat.com/docs/manuals/dir-server/release-notes/7.1SP7/index.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0602.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0858.htmlhttp://www.securityfocus.com/bid/30872http://www.vupen.com/english/advisories/2008/2480https://bugzilla.redhat.com/show_bug.cgi?id=458977https://exchange.xforce.ibmcloud.com/vulnerabilities/44731https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6118https://rhn.redhat.com/errata/RHSA-2008-0596.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-September/msg00521.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-September/msg00708.html
2008-08-29
Published