CVE-2011-0704

Severity
5.9MEDIUM
EPSS
0.5%
top 36.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 4
Latest updateMay 14

Description

389 Directory Server 1.2.7.5, when built with mozldap, allows remote attackers to cause a denial of service (replica crash) by sending an empty modify request.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 2.2 | Impact: 3.6

Affected Packages2 packages

Ubuntu389-ds-base< 1.3.7.10-1ubuntu1+2

🔴Vulnerability Details

3
GHSA
GHSA-wxv3-8897-8hq4: 389 Directory Server 12022-05-14
OSV
CVE-2011-0704: 389 Directory Server 12018-05-04
CVEList
CVE-2011-0704: 389 Directory Server 12018-05-04

📋Vendor Advisories

1
Red Hat
389: replica crashes due to empty modify request when built with mozldap2011-02-15

💬Community

1
Bugzilla
CVE-2011-0704 389: replica crashes due to empty modify request when built with mozldap2011-02-11
CVE-2011-0704 (MEDIUM CVSS 5.9) | 389 Directory Server 1.2.7.5 | cvebase.io