Severity
7.5HIGH
EPSS
14.7%
top 5.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 7
Latest updateMay 14

Description

An out-of-bounds memory read flaw was found in the way 389-ds-base handled certain LDAP search filters, affecting all versions including 1.4.x. A remote, unauthenticated attacker could potentially use this flaw to make ns-slapd crash via a specially crafted LDAP request, thus resulting in denial of service.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages6 packages

Debian389-ds-base< 1.3.7.10-1+2
CVEListV5red_hat,_inc./389-ds-baseall versions including upstream 1.4.x
NVDredhat/enterprise_linux_server6.0, 7.0, 7.4+2

Patches

🔴Vulnerability Details

3
GHSA
GHSA-g83g-r7vx-57fv: An out-of-bounds memory read flaw was found in the way 389-ds-base handled certain LDAP search filters, affecting all versions including 12022-05-14
OSV
CVE-2018-1054: An out-of-bounds memory read flaw was found in the way 389-ds-base handled certain LDAP search filters, affecting all versions including 12018-03-07
CVEList
CVE-2018-1054: An out-of-bounds memory read flaw was found in the way 389-ds-base handled certain LDAP search filters, affecting all versions including 12018-03-07

📋Vendor Advisories

2
Red Hat
389-ds-base: remote Denial of Service (DoS) via search filters in SetUnicodeStringFromUTF_8 in collate.c2018-03-05
Debian
CVE-2018-1054: 389-ds-base - An out-of-bounds memory read flaw was found in the way 389-ds-base handled certa...2018

💬Community

3
Bugzilla
CVE-2018-10805 ImageMagick: Memory leak in ReadYCBCRImage2018-05-11
Bugzilla
CVE-2018-1054 389-ds-base: remote Denial of Service (DoS) via search filters in SetUnicodeStringFromUTF_8 in collate.c [fedora-all]2018-03-05
Bugzilla
CVE-2018-1054 389-ds-base: remote Denial of Service (DoS) via search filters in SetUnicodeStringFromUTF_8 in collate.c2018-01-22
CVE-2018-1054 (HIGH CVSS 7.5) | An out-of-bounds memory read flaw w | cvebase.io