CVE-2018-1089
published 2018-05-09CVE-2018-1089: 389-ds-base before versions 1.4.0.9, 1.3.8.1, 1.3.6.15 did not properly handle long search filters with characters needing escapes, possibly leading to buffer…
PriorityP342high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
4.24%
89.9th percentile
389-ds-base before versions 1.4.0.9, 1.3.8.1, 1.3.6.15 did not properly handle long search filters with characters needing escapes, possibly leading to buffer overflows. A remote, unauthenticated attacker could potentially use this flaw to make ns-slapd crash via a specially crafted LDAP request, thus resulting in denial of service.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | 389-ds-base | < 389-ds-base 1.3.8.2-1 (bookworm) | 389-ds-base 1.3.8.2-1 (bookworm) |
| debian | debian_linux | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | >= 1.3.6.0 < 1.3.6.15 | 1.3.6.15 |
| fedoraproject | 389_directory_server | >= 1.4.0.0 < 1.4.0.9 | 1.4.0.9 |
| port389 | 389-ds-base | >= 0 < 1.3.8.2-1 | 1.3.8.2-1 |
| port389 | 389-ds-base | >= 0 < 1.3.8.2-1 | 1.3.8.2-1 |
| port389 | 389-ds-base | >= 0 < 1.3.8.2-1 | 1.3.8.2-1 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4xv3-w7vq-3g6v: 389-ds-base before versions 1
ghsa_unreviewed·2022-05-13
CVE-2018-1089 [HIGH] CWE-119 GHSA-4xv3-w7vq-3g6v: 389-ds-base before versions 1
389-ds-base before versions 1.4.0.9, 1.3.8.1, 1.3.6.15 did not properly handle long search filters with characters needing escapes, possibly leading to buffer overflows. A remote, unauthenticated attacker could potentially use this flaw to make ns-slapd crash via a specially crafted LDAP request, thus resulting in denial of service.
OSV
CVE-2018-1089: 389-ds-base before versions 1
osv·2018-05-09·CVSS 7.5
CVE-2018-1089 [HIGH] CVE-2018-1089: 389-ds-base before versions 1
389-ds-base before versions 1.4.0.9, 1.3.8.1, 1.3.6.15 did not properly handle long search filters with characters needing escapes, possibly leading to buffer overflows. A remote, unauthenticated attacker could potentially use this flaw to make ns-slapd crash via a specially crafted LDAP request, thus resulting in denial of service.
Red Hat
389-ds-base: ns-slapd crash via large filter value in ldapsearch
vendor_redhat·2018-05-07·CVSS 7.5
CVE-2018-1089 [HIGH] CWE-122 389-ds-base: ns-slapd crash via large filter value in ldapsearch
389-ds-base: ns-slapd crash via large filter value in ldapsearch
389-ds-base before versions 1.4.0.9, 1.3.8.1, 1.3.6.15 did not properly handle long search filters with characters needing escapes, possibly leading to buffer overflows. A remote, unauthenticated attacker could potentially use this flaw to make ns-slapd crash via a specially crafted LDAP request, thus resulting in denial of service.
It was found that 389-ds-base did not properly handle long search filters with characters needing escapes, possibly leading to buffer overflows. A remote, unauthenticated attacker could potentially use this flaw to make ns-slapd crash via a specially crafted LDAP request, thus resulting in denial of service.
Package: 389-ds-base (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2018-1089: 389-ds-base - 389-ds-base before versions 1.4.0.9, 1.3.8.1, 1.3.6.15 did not properly handle l...
vendor_debian·2018·CVSS 7.5
CVE-2018-1089 [HIGH] CVE-2018-1089: 389-ds-base - 389-ds-base before versions 1.4.0.9, 1.3.8.1, 1.3.6.15 did not properly handle l...
389-ds-base before versions 1.4.0.9, 1.3.8.1, 1.3.6.15 did not properly handle long search filters with characters needing escapes, possibly leading to buffer overflows. A remote, unauthenticated attacker could potentially use this flaw to make ns-slapd crash via a specially crafted LDAP request, thus resulting in denial of service.
Scope: local
bookworm: resolved (fixed in 1.3.8.2-1)
bullseye: resolved (fixed in 1.3.8.2-1)
sid: resolved (fixed in 1.3.8.2-1)
trixie: resolved (fixed in 1.3.8.2-1)
No detection rules found.
No public exploits indexed.
Bugzilla
389-ds-base: Memory exhaustion in ns-slapd can allow an authenticated remote attacker to cause a denial of service
bugzilla·2018-06-21·CVSS 7.5
CVE-2018-1089 [HIGH] 389-ds-base: Memory exhaustion in ns-slapd can allow an authenticated remote attacker to cause a denial of service
389-ds-base: Memory exhaustion in ns-slapd can allow an authenticated remote attacker to cause a denial of service
The 389 Directory Server has a memory exhaustion vulnerability in ns-slapd due to the lack of attribute length restrictions. A remote authenticated attacker could exploit this via an attribute like 'gecos' to upload data of arbitrary size and cause a denial of service.
Discussion:
Need to confirm the affected component and that this is a separate issue to CVE-2018-1089 before assigning a CVE.
---
Unable to reproduce on 389-ds-base-1.2.11.15-95 RHEL6 32bit or 1.3.7.5 on RHEL7. Waiting on response from reporter. Will re-open and re-investigate if new information comes to light.
Bugzilla
CVE-2018-1089 389-ds-base: ns-slapd crash via large filter value in ldapsearch [fedora-all]
bugzilla·2018-05-07·CVSS 7.5
CVE-2018-1089 [HIGH] CVE-2018-1089 389-ds-base: ns-slapd crash via large filter value in ldapsearch [fedora-all]
CVE-2018-1089 389-ds-base: ns-slapd crash via large filter value in ldapsearch [fedora-all]
Use the following template to for the 'fedpkg update' request to submit an
update for this issue as it contains the top-level parent bug(s) as well as
this tracking bug. This will ensure that all associated bugs get updated
when new packages are pushed to stable.
# bugfix, security, enhancement, newpackage (required)
type=security
# testing, stable
request=testing
# Bug numbers: 1234,9876
bugs=1559802,1575671
# Description of your update
notes=Security fix for [PUT CVEs HERE]
# Enable request automation based on the stable/unstable karma thresholds
autokarma=True
stable_karma=3
unstable_karma=-3
# Automatically close bugs when this marked as stable
close_bugs=True
# Suggest that users resta
Bugzilla
CVE-2018-1089 389-ds-base: ns-slapd crash via large filter value in ldapsearch
bugzilla·2018-03-23·CVSS 7.5
CVE-2018-1089 [HIGH] CVE-2018-1089 389-ds-base: ns-slapd crash via large filter value in ldapsearch
CVE-2018-1089 389-ds-base: ns-slapd crash via large filter value in ldapsearch
It is possible to crash ns-slapd (and ipa-dnskeysyncd afterwards) with crafted ldapsearch query with very long filter value both as anonymous or authenticated user. The crash can be similarly triggered with a query via the FreeIPA API as an authenticated user.
Discussion:
Acknowledgments:
Name: Greg Kubok
---
Created 389-ds-base tracking bugs for this issue:
Affects: fedora-all [bug 1575671]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2018:1364 https://access.redhat.com/errata/RHSA-2018:1364
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2018:1380 https://access.redhat.com/errata/RHSA-2018:1380
http://www.securityfocus.com/bid/104137https://access.redhat.com/errata/RHSA-2018:1364https://access.redhat.com/errata/RHSA-2018:1380https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1089https://lists.debian.org/debian-lts-announce/2018/07/msg00018.htmlhttp://www.securityfocus.com/bid/104137https://access.redhat.com/errata/RHSA-2018:1364https://access.redhat.com/errata/RHSA-2018:1380https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1089https://lists.debian.org/debian-lts-announce/2018/07/msg00018.html
2018-05-09
Published