CVE-2016-0741
published 2016-04-19CVE-2016-0741: slapd/connection.c in 389 Directory Server (formerly Fedora Directory Server) 1.3.4.x before 1.3.4.7 allows remote attackers to cause a denial of service…
PriorityP335high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
3.96%
89.3th percentile
slapd/connection.c in 389 Directory Server (formerly Fedora Directory Server) 1.3.4.x before 1.3.4.7 allows remote attackers to cause a denial of service (infinite loop and connection blocking) by leveraging an abnormally closed connection.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | 389-ds-base | < 389-ds-base 1.3.4.8-1 (bookworm) | 389-ds-base 1.3.4.8-1 (bookworm) |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| port389 | 389-ds-base | >= 0 < 1.3.4.8-1 | 1.3.4.8-1 |
| port389 | 389-ds-base | >= 0 < 1.3.4.8-1 | 1.3.4.8-1 |
| port389 | 389-ds-base | >= 0 < 1.3.4.8-1 | 1.3.4.8-1 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_hpc_node | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hx2c-r32g-8w55: slapd/connection
ghsa_unreviewed·2022-05-17
CVE-2016-0741 [HIGH] GHSA-hx2c-r32g-8w55: slapd/connection
slapd/connection.c in 389 Directory Server (formerly Fedora Directory Server) 1.3.4.x before 1.3.4.7 allows remote attackers to cause a denial of service (infinite loop and connection blocking) by leveraging an abnormally closed connection.
OSV
CVE-2016-0741: slapd/connection
osv·2016-04-19·CVSS 7.5
CVE-2016-0741 [HIGH] CVE-2016-0741: slapd/connection
slapd/connection.c in 389 Directory Server (formerly Fedora Directory Server) 1.3.4.x before 1.3.4.7 allows remote attackers to cause a denial of service (infinite loop and connection blocking) by leveraging an abnormally closed connection.
Red Hat
389-ds-base: worker threads do not detect abnormally closed connections causing DoS
vendor_redhat·2016-01-15·CVSS 7.5
CVE-2016-0741 [HIGH] CWE-772 389-ds-base: worker threads do not detect abnormally closed connections causing DoS
389-ds-base: worker threads do not detect abnormally closed connections causing DoS
slapd/connection.c in 389 Directory Server (formerly Fedora Directory Server) 1.3.4.x before 1.3.4.7 allows remote attackers to cause a denial of service (infinite loop and connection blocking) by leveraging an abnormally closed connection.
An infinite-loop vulnerability was discovered in the 389 directory server, where the server failed to correctly handle unexpectedly closed client connections. A remote attacker able to connect to the server could use this flaw to make the directory server consume an excessive amount of CPU and stop accepting connections (denial of service).
Package: 389-ds-base (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2016-0741: 389-ds-base - slapd/connection.c in 389 Directory Server (formerly Fedora Directory Server) 1....
vendor_debian·2016·CVSS 7.5
CVE-2016-0741 [HIGH] CVE-2016-0741: 389-ds-base - slapd/connection.c in 389 Directory Server (formerly Fedora Directory Server) 1....
slapd/connection.c in 389 Directory Server (formerly Fedora Directory Server) 1.3.4.x before 1.3.4.7 allows remote attackers to cause a denial of service (infinite loop and connection blocking) by leveraging an abnormally closed connection.
Scope: local
bookworm: resolved (fixed in 1.3.4.8-1)
bullseye: resolved (fixed in 1.3.4.8-1)
sid: resolved (fixed in 1.3.4.8-1)
trixie: resolved (fixed in 1.3.4.8-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-0741 389-ds-base: Worker threads do not detect abnormally closed connections causing DoS [epel-5]
bugzilla·2016-01-18·CVSS 7.5
CVE-2016-0741 [HIGH] CVE-2016-0741 389-ds-base: Worker threads do not detect abnormally closed connections causing DoS [epel-5]
CVE-2016-0741 389-ds-base: Worker threads do not detect abnormally closed connections causing DoS [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-5 tracking bug fo
Bugzilla
CVE-2016-0741 389-ds-base: Worker threads do not detect abnormally closed connections causing DoS [fedora-all]
bugzilla·2016-01-18·CVSS 7.5
CVE-2016-0741 [HIGH] CVE-2016-0741 389-ds-base: Worker threads do not detect abnormally closed connections causing DoS [fedora-all]
CVE-2016-0741 389-ds-base: Worker threads do not detect abnormally closed connections causing DoS [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affect
Bugzilla
CVE-2016-0741 389-ds-base: worker threads do not detect abnormally closed connections causing DoS
bugzilla·2016-01-18·CVSS 7.5
CVE-2016-0741 [HIGH] CVE-2016-0741 389-ds-base: worker threads do not detect abnormally closed connections causing DoS
CVE-2016-0741 389-ds-base: worker threads do not detect abnormally closed connections causing DoS
Quoting from the upstream bug:
When a connection is abruptly closed due to an error, and there is still some data left to be read (buffer offset vs buffer bytes), connection_threadmain starts to loop. The connection is marked as closed, which prevents the buffer bytes/offset to be updated (e.g. in connection_read_operation()). So the worker thread endlessly tries to read the "data" over and over, but it should just remove the connection from the conn table since it's marked as closed. While it's looping it's repeatedly taking the factory extension lock which creates a lot of contention with the other worker threads. Ultimately, all the worker threads are trying to read data on closed connect
http://directory.fedoraproject.org/docs/389ds/releases/release-1-3-4-7.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0204.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.securityfocus.com/bid/82343https://fedorahosted.org/389/changeset/cd45d032421b0ecf76d8cbb9b1c3aeef7680d9a2/https://fedorahosted.org/389/ticket/48412http://directory.fedoraproject.org/docs/389ds/releases/release-1-3-4-7.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0204.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.securityfocus.com/bid/82343https://fedorahosted.org/389/changeset/cd45d032421b0ecf76d8cbb9b1c3aeef7680d9a2/https://fedorahosted.org/389/ticket/48412
2016-04-19
Published