CVE-2017-2668
published 2018-06-22CVE-2017-2668: 389-ds-base before versions 1.3.5.17 and 1.3.6.10 is vulnerable to an invalid pointer dereference in the way LDAP bind requests are handled. A remote…
PriorityP432medium6.5CVSS 3.0
AVNACLPRNUIRSUCNINAH
EPSS
2.63%
83.8th percentile
389-ds-base before versions 1.3.5.17 and 1.3.6.10 is vulnerable to an invalid pointer dereference in the way LDAP bind requests are handled. A remote unauthenticated attacker could use this flaw to make ns-slapd crash via a specially crafted LDAP bind request, resulting in denial of service.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | 389-ds-base | < 389-ds-base 1.3.5.17-1 (bookworm) | 389-ds-base 1.3.5.17-1 (bookworm) |
| fedoraproject | 389_directory_server | >= 1.3.5.0 < 1.3.5.17 | 1.3.5.17 |
| fedoraproject | 389_directory_server | >= 1.3.6.0 < 1.3.6.10 | 1.3.6.10 |
| port389 | 389-ds-base | >= 0 < 1.3.5.17-1 | 1.3.5.17-1 |
| port389 | 389-ds-base | >= 0 < 1.3.5.17-1 | 1.3.5.17-1 |
| port389 | 389-ds-base | >= 0 < 1.3.5.17-1 | 1.3.5.17-1 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
389-ds-base: Remote crash via crafted LDAP messages
vendor_redhat·2017-04-10·CVSS 6.5
CVE-2017-2668 [MEDIUM] CWE-119 389-ds-base: Remote crash via crafted LDAP messages
389-ds-base: Remote crash via crafted LDAP messages
389-ds-base before versions 1.3.5.17 and 1.3.6.10 is vulnerable to an invalid pointer dereference in the way LDAP bind requests are handled. A remote unauthenticated attacker could use this flaw to make ns-slapd crash via a specially crafted LDAP bind request, resulting in denial of service.
An invalid pointer dereference flaw was found in the way 389-ds-base handled LDAP bind requests. A remote unauthenticated attacker could use this flaw to make ns-slapd crash via a specially crafted LDAP bind request, resulting in denial of service.
Debian
CVE-2017-2668: 389-ds-base - 389-ds-base before versions 1.3.5.17 and 1.3.6.10 is vulnerable to an invalid po...
vendor_debian·2017·CVSS 6.5
CVE-2017-2668 [MEDIUM] CVE-2017-2668: 389-ds-base - 389-ds-base before versions 1.3.5.17 and 1.3.6.10 is vulnerable to an invalid po...
389-ds-base before versions 1.3.5.17 and 1.3.6.10 is vulnerable to an invalid pointer dereference in the way LDAP bind requests are handled. A remote unauthenticated attacker could use this flaw to make ns-slapd crash via a specially crafted LDAP bind request, resulting in denial of service.
Scope: local
bookworm: resolved (fixed in 1.3.5.17-1)
bullseye: resolved (fixed in 1.3.5.17-1)
sid: resolved (fixed in 1.3.5.17-1)
trixie: resolved (fixed in 1.3.5.17-1)
GHSA
GHSA-8xf9-83fh-q7rf: 389-ds-base before versions 1
ghsa_unreviewed·2022-05-13
CVE-2017-2668 [MEDIUM] CWE-476 GHSA-8xf9-83fh-q7rf: 389-ds-base before versions 1
389-ds-base before versions 1.3.5.17 and 1.3.6.10 is vulnerable to an invalid pointer dereference in the way LDAP bind requests are handled. A remote unauthenticated attacker could use this flaw to make ns-slapd crash via a specially crafted LDAP bind request, resulting in denial of service.
OSV
CVE-2017-2668: 389-ds-base before versions 1
osv·2018-06-22·CVSS 6.5
CVE-2017-2668 [MEDIUM] CVE-2017-2668: 389-ds-base before versions 1
389-ds-base before versions 1.3.5.17 and 1.3.6.10 is vulnerable to an invalid pointer dereference in the way LDAP bind requests are handled. A remote unauthenticated attacker could use this flaw to make ns-slapd crash via a specially crafted LDAP bind request, resulting in denial of service.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-5661 fop: XML external entity processing vulnerability
bugzilla·2017-04-19·CVSS 7.3
CVE-2017-5661 [HIGH] CVE-2017-5661 fop: XML external entity processing vulnerability
CVE-2017-5661 fop: XML external entity processing vulnerability
In Apache FOP before 2.2, files lying on the filesystem of the server which uses FOP can be revealed to arbitrary users who send maliciously formed SVG files. The file types that can be shown depend on the user context in which the exploitable application is running. If the user is root a full compromise of the server - including confidential or sensitive files - would be possible. XXE can also be used to attack the availability of the server via denial of service as the references within a xml document can trivially trigger an amplification attack.
References:
https://xmlgraphics.apache.org/security.html
http://seclists.org/oss-sec/2017/q2/86
Discussion:
Upstream bug report:
https://issues.apache.org/jira/browse/FOP-2668
Bugzilla
CVE-2017-2668 389-ds-base: Remote crash via crafted LDAP messages [fedora-all]
bugzilla·2017-04-10·CVSS 6.5
CVE-2017-2668 [MEDIUM] CVE-2017-2668 389-ds-base: Remote crash via crafted LDAP messages [fedora-all]
CVE-2017-2668 389-ds-base: Remote crash via crafted LDAP messages [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of
Bugzilla
CVE-2017-2668 389-ds-base: Remote crash via crafted LDAP messages
bugzilla·2017-03-28·CVSS 6.5
CVE-2017-2668 [MEDIUM] CVE-2017-2668 389-ds-base: Remote crash via crafted LDAP messages
CVE-2017-2668 389-ds-base: Remote crash via crafted LDAP messages
An invalid pointer dereference flaw was found in the way 389-ds-base handled LDAP bind requests. A remote unauthenticated attacker could use this flaw to make ns-slapd crash via a specially crafted LDAP bind request, resulting in denial of service.
Discussion:
Acknowledgments:
Name: Joachim Jabs (F24)
---
Created 389-ds-base tracking bugs for this issue:
Affects: fedora-all [bug 1440613]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2017:0893 https://access.redhat.com/errata/RHSA-2017:0893
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2017:0920 https://access.redhat.com/errata/RHSA-2017:0920
---
For tracking
http://www.securityfocus.com/bid/97524https://access.redhat.com/errata/RHSA-2017:0893https://access.redhat.com/errata/RHSA-2017:0920https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2668https://pagure.io/389-ds-base/issue/49220http://www.securityfocus.com/bid/97524https://access.redhat.com/errata/RHSA-2017:0893https://access.redhat.com/errata/RHSA-2017:0920https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2668https://pagure.io/389-ds-base/issue/49220
2018-06-22
Published