CVE-2017-2591
published 2018-04-30CVE-2017-2591: 389-ds-base before version 1.3.6 is vulnerable to an improperly NULL terminated array in the uniqueness_entry_to_config() function in the "attribute…
PriorityP340high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
2.97%
85.7th percentile
389-ds-base before version 1.3.6 is vulnerable to an improperly NULL terminated array in the uniqueness_entry_to_config() function in the "attribute uniqueness" plugin of 389 Directory Server. An authenticated, or possibly unauthenticated, attacker could use this flaw to force an out-of-bound heap memory read, possibly triggering a crash of the LDAP service.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | 389-ds-base | < 389-ds-base 1.3.5.15-2 (bookworm) | 389-ds-base 1.3.5.15-2 (bookworm) |
| fedoraproject | 389_directory_server | < 1.3.6 | 1.3.6 |
| port389 | 389-ds-base | >= 0 < 1.3.5.15-2 | 1.3.5.15-2 |
| port389 | 389-ds-base | >= 0 < 1.3.5.15-2 | 1.3.5.15-2 |
| port389 | 389-ds-base | >= 0 < 1.3.5.15-2 | 1.3.5.15-2 |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian3.7LOW
vendor_redhat3.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cmhq-25mx-42j8: 389-ds-base before version 1
ghsa_unreviewed·2022-05-13
CVE-2017-2591 [HIGH] CWE-125 GHSA-cmhq-25mx-42j8: 389-ds-base before version 1
389-ds-base before version 1.3.6 is vulnerable to an improperly NULL terminated array in the uniqueness_entry_to_config() function in the "attribute uniqueness" plugin of 389 Directory Server. An authenticated, or possibly unauthenticated, attacker could use this flaw to force an out-of-bound heap memory read, possibly triggering a crash of the LDAP service.
OSV
CVE-2017-2591: 389-ds-base before version 1
osv·2018-04-30·CVSS 7.5
CVE-2017-2591 [HIGH] CVE-2017-2591: 389-ds-base before version 1
389-ds-base before version 1.3.6 is vulnerable to an improperly NULL terminated array in the uniqueness_entry_to_config() function in the "attribute uniqueness" plugin of 389 Directory Server. An authenticated, or possibly unauthenticated, attacker could use this flaw to force an out-of-bound heap memory read, possibly triggering a crash of the LDAP service.
Debian
CVE-2017-2591: 389-ds-base - 389-ds-base before version 1.3.6 is vulnerable to an improperly NULL terminated ...
vendor_debian·2017·CVSS 3.7
CVE-2017-2591 [LOW] CVE-2017-2591: 389-ds-base - 389-ds-base before version 1.3.6 is vulnerable to an improperly NULL terminated ...
389-ds-base before version 1.3.6 is vulnerable to an improperly NULL terminated array in the uniqueness_entry_to_config() function in the "attribute uniqueness" plugin of 389 Directory Server. An authenticated, or possibly unauthenticated, attacker could use this flaw to force an out-of-bound heap memory read, possibly triggering a crash of the LDAP service.
Scope: local
bookworm: resolved (fixed in 1.3.5.15-2)
bullseye: resolved (fixed in 1.3.5.15-2)
sid: resolved (fixed in 1.3.5.15-2)
trixie: resolved (fixed in 1.3.5.15-2)
Red Hat
389-ds-base: Heap buffer overflow in uiduniq.c
vendor_redhat·2016-09-13·CVSS 3.7
CVE-2017-2591 [LOW] CWE-122 389-ds-base: Heap buffer overflow in uiduniq.c
389-ds-base: Heap buffer overflow in uiduniq.c
389-ds-base before version 1.3.6 is vulnerable to an improperly NULL terminated array in the uniqueness_entry_to_config() function in the "attribute uniqueness" plugin of 389 Directory Server. An authenticated, or possibly unauthenticated, attacker could use this flaw to force an out-of-bound heap memory read, possibly triggering a crash of the LDAP service.
It was found that the uniqueness_entry_to_config() function, used by the "attribute uniqueness" plugin of 389 Directory Server, did not properly NULL terminate an array used in some configuration. An authenticated, or possibly unauthenticated, attacker could use this flaw to force an out-of-bound heap memory read, possibly triggering a crash of the LDAP service.
Statement: Red Hat Produ
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-2591 389-ds-base: Heap buffer overflow in uiduniq.c
bugzilla·2016-10-04·CVSS 3.7
CVE-2017-2591 [LOW] CVE-2017-2591 389-ds-base: Heap buffer overflow in uiduniq.c
CVE-2017-2591 389-ds-base: Heap buffer overflow in uiduniq.c
The "attribute uniqueness" plugin did not properly NULL-terminate an array when building up its configuration, if a so called 'old-style' configuration, was being used (Using nsslapd-pluginarg parameters) .
A attacker, authenticated, but possibly also unauthenticated, could possibly force the plugin to read beyond allocated memory and trigger a segfault.
The crash could also possibly be triggered accidentally.
Upstream patch :https://fedorahosted.org/389/changeset/ffda694dd622b31277da07be76d3469fad86150f/
Affected versions : from 1.3.4.0
Fixed version : 1.3.6
Upstream bug report : https://fedorahosted.org/389/ticket/48986
Discussion:
Created 389-ds-base tracking bugs for this issue:
Affects: fedora-all [bug 1381483]
---
Bugzilla
CVE-2017-2591 389-ds-base: various flaws [fedora-all]
bugzilla·2016-10-04·CVSS 3.7
CVE-2017-2591 [LOW] CVE-2017-2591 389-ds-base: various flaws [fedora-all]
CVE-2017-2591 389-ds-base: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While only
one t
2018-04-30
Published