CVE-2013-0312389 Directory Server vulnerability

CWE-1899 documents7 sources
Severity
5.0MEDIUMNVD
EPSS
1.4%
top 19.68%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 13
Latest updateMay 5

Description

389 Directory Server before 1.3.0.4 allows remote attackers to cause a denial of service (crash) via a zero length LDAP control sequence.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

🔴Vulnerability Details

3
GHSA
GHSA-j8v7-ppwf-h5jg: 389 Directory Server before 12022-05-05
OSV
CVE-2013-0312: 389 Directory Server before 12013-03-13
CVEList
CVE-2013-0312: 389 Directory Server before 12013-03-13

📋Vendor Advisories

2
Red Hat
389-ds: unauthenticated denial of service vulnerability in handling of LDAPv3 control data2013-03-11
Debian
CVE-2013-0312: 389-ds-base - 389 Directory Server before 1.3.0.4 allows remote attackers to cause a denial of...2013

💬Community

3
Bugzilla
CVE-2013-0312 389-ds: unauthenticated denial of service vulnerability in handling of LDAPv3 control data [fedora-all]2013-03-11
Bugzilla
CVE-2013-0312 389-ds: unauthenticated denial of service vulnerability in handling of LDAPv3 control data [epel-5]2013-03-11
Bugzilla
CVE-2013-0312 389-ds: unauthenticated denial of service vulnerability in handling of LDAPv3 control data2013-02-20
CVE-2013-0312 — 389 Directory Server vulnerability | cvebase