CVE-2017-2668Improper Restriction of Operations within the Bounds of a Memory Buffer in 389 Directory Server

Severity
6.5MEDIUMNVD
EPSS
7.6%
top 8.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 22
Latest updateMay 13

Description

389-ds-base before versions 1.3.5.17 and 1.3.6.10 is vulnerable to an invalid pointer dereference in the way LDAP bind requests are handled. A remote unauthenticated attacker could use this flaw to make ns-slapd crash via a specially crafted LDAP bind request, resulting in denial of service.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages5 packages

🔴Vulnerability Details

3
GHSA
GHSA-8xf9-83fh-q7rf: 389-ds-base before versions 12022-05-13
CVEList
CVE-2017-2668: 389-ds-base before versions 12018-06-22
OSV
CVE-2017-2668: 389-ds-base before versions 12018-06-22

📋Vendor Advisories

2
Red Hat
389-ds-base: Remote crash via crafted LDAP messages2017-04-10
Debian
CVE-2017-2668: 389-ds-base - 389-ds-base before versions 1.3.5.17 and 1.3.6.10 is vulnerable to an invalid po...2017

💬Community

3
Bugzilla
CVE-2017-5661 fop: XML external entity processing vulnerability2017-04-19
Bugzilla
CVE-2017-2668 389-ds-base: Remote crash via crafted LDAP messages [fedora-all]2017-04-10
Bugzilla
CVE-2017-2668 389-ds-base: Remote crash via crafted LDAP messages2017-03-28
CVE-2017-2668 — 389 Directory Server vulnerability | cvebase