cbcvebase.
CVE-2013-0336
published 2014-11-03

CVE-2013-0336: The ipapwd_chpwop function in daemons/ipa-slapi-plugins/ipa-pwd-extop/ipa_pwd_extop.c in the directory server (dirsrv) in FreeIPA before 3.2.0 allows remote…

PriorityP423medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.76%
84.6th percentile
The ipapwd_chpwop function in daemons/ipa-slapi-plugins/ipa-pwd-extop/ipa_pwd_extop.c in the directory server (dirsrv) in FreeIPA before 3.2.0 allows remote attackers to cause a denial of service (crash) via a connection request without a username/dn, related to the 389 directory server.

Affected

12 ranges
VendorProductVersion rangeFixed in
debian389-ds-base< 389-ds-base 1.3.2.9-1 (bookworm)389-ds-base 1.3.2.9-1 (bookworm)
port389389-ds-base>= 0 < 1.3.2.9-11.3.2.9-1
port389389-ds-base>= 0 < 1.3.2.9-11.3.2.9-1
port389389-ds-base>= 0 < 1.3.2.9-11.3.2.9-1
redhatfreeipa<= 3.1.5
redhatfreeipa
redhatfreeipa
redhatfreeipa
redhatfreeipa
redhatfreeipa
redhatfreeipa
redhatfreeipa

CVSS provenance

nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.