CVE-2018-14648
published 2019-08-02CVE-2018-14648: It was found that the fix for CVE-2018-14648 in 389-ds-base, versions 1.4.0.x before 1.4.0.17, was incorrectly applied in RHEL 7.5. An attacker would still be…
PriorityP343high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
6.29%
92.8th percentile
It was found that the fix for CVE-2018-14648 in 389-ds-base, versions 1.4.0.x before 1.4.0.17, was incorrectly applied in RHEL 7.5. An attacker would still be able to provoke excessive CPU consumption leading to a denial of service.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | 389-ds-base | < 389-ds-base 1.4.0.18-1 (bookworm) | 389-ds-base 1.4.0.18-1 (bookworm) |
| debian | 389-ds-base | — | — |
| debian | debian_linux | — | — |
| fedoraproject | 389_directory_server | < 1.4.0.17 | 1.4.0.17 |
| fedoraproject | 389_directory_server | >= 1.4.0.0 < 1.4.0.17 | 1.4.0.17 |
| port389 | 389-ds-base | >= 0 < 1.4.0.18-1 | 1.4.0.18-1 |
| port389 | 389-ds-base | >= 0 < 1.4.0.18-1 | 1.4.0.18-1 |
| port389 | 389-ds-base | >= 0 < 1.4.0.18-1 | 1.4.0.18-1 |
| redhat | 389-ds-base | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_server_eus | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
389-ds-base: Insufficient fix for CVE-2018-14648 denial of service in RHEL-7.5
vendor_redhat·2019-06-19·CVSS 7.5
CVE-2019-10171 [HIGH] CWE-770 389-ds-base: Insufficient fix for CVE-2018-14648 denial of service in RHEL-7.5
389-ds-base: Insufficient fix for CVE-2018-14648 denial of service in RHEL-7.5
It was found that the fix for CVE-2018-14648 in 389-ds-base, versions 1.4.0.x before 1.4.0.17, was incorrectly applied in RHEL 7.5. An attacker would still be able to provoke excessive CPU consumption leading to a denial of service.
It was found that the fix for CVE-2018-14648 was incorrectly applied in RHEL 7.5. An attacker would still be able to provoke excessive CPU consumption leading to a denial of service.
Package: 389-ds-base (Red Hat Enterprise Linux 7) - Affected
Debian
CVE-2019-10171: 389-ds-base - It was found that the fix for CVE-2018-14648 in 389-ds-base, versions 1.4.0.x be...
vendor_debian·2019·CVSS 7.5
CVE-2019-10171 [HIGH] CVE-2019-10171: 389-ds-base - It was found that the fix for CVE-2018-14648 in 389-ds-base, versions 1.4.0.x be...
It was found that the fix for CVE-2018-14648 in 389-ds-base, versions 1.4.0.x before 1.4.0.17, was incorrectly applied in RHEL 7.5. An attacker would still be able to provoke excessive CPU consumption leading to a denial of service.
Scope: local
bookworm: resolved
bullseye: resolved
sid: resolved
trixie: resolved
Red Hat
389-ds-base: Mishandled search requests in servers/slapd/search.c:do_search() allows for denial of service
vendor_redhat·2018-09-21·CVSS 7.5
CVE-2018-14648 [HIGH] CWE-400 389-ds-base: Mishandled search requests in servers/slapd/search.c:do_search() allows for denial of service
389-ds-base: Mishandled search requests in servers/slapd/search.c:do_search() allows for denial of service
A flaw was found in 389 Directory Server. A specially crafted search query could lead to excessive CPU consumption in the do_search() function. An unauthenticated attacker could use this flaw to provoke a denial of service.
It was found that a specially crafted search query could lead to excessive CPU consumption in the do_search() function. An unauthenticated attacker could use this flaw to provoke a denial of service.
Package: 389-ds-base (Red Hat Enterprise Linux 6) - Will not fix
Package: 389-ds-base (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2018-14648: 389-ds-base - A flaw was found in 389 Directory Server. A specially crafted search query could...
vendor_debian·2018·CVSS 7.5
CVE-2018-14648 [HIGH] CVE-2018-14648: 389-ds-base - A flaw was found in 389 Directory Server. A specially crafted search query could...
A flaw was found in 389 Directory Server. A specially crafted search query could lead to excessive CPU consumption in the do_search() function. An unauthenticated attacker could use this flaw to provoke a denial of service.
Scope: local
bookworm: resolved (fixed in 1.4.0.18-1)
bullseye: resolved (fixed in 1.4.0.18-1)
sid: resolved (fixed in 1.4.0.18-1)
trixie: resolved (fixed in 1.4.0.18-1)
GHSA
GHSA-9cc6-43cm-mf7x: It was found that the fix for CVE-2018-14648 in 389-ds-base, versions 1
ghsa_unreviewed·2022-05-24·CVSS 7.5
CVE-2019-10171 [HIGH] CWE-770 GHSA-9cc6-43cm-mf7x: It was found that the fix for CVE-2018-14648 in 389-ds-base, versions 1
It was found that the fix for CVE-2018-14648 in 389-ds-base, versions 1.4.0.x before 1.4.0.17, was incorrectly applied in RHEL 7.5. An attacker would still be able to provoke excessive CPU consumption leading to a denial of service.
GHSA
GHSA-pghh-mx5f-3vcv: A flaw was found in 389 Directory Server
ghsa_unreviewed·2022-05-13
CVE-2018-14648 [HIGH] CWE-400 GHSA-pghh-mx5f-3vcv: A flaw was found in 389 Directory Server
A flaw was found in 389 Directory Server. A specially crafted search query could lead to excessive CPU consumption in the do_search() function. An unauthenticated attacker could use this flaw to provoke a denial of service.
OSV
CVE-2018-14648: A flaw was found in 389 Directory Server
osv·2018-09-28·CVSS 7.5
CVE-2018-14648 [HIGH] CVE-2018-14648: A flaw was found in 389 Directory Server
A flaw was found in 389 Directory Server. A specially crafted search query could lead to excessive CPU consumption in the do_search() function. An unauthenticated attacker could use this flaw to provoke a denial of service.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-10171 389-ds-base: Insufficient fix for CVE-2018-14648 denial of service in RHEL-7.5
bugzilla·2019-06-19·CVSS 7.5
CVE-2019-10171 [HIGH] CVE-2019-10171 389-ds-base: Insufficient fix for CVE-2018-14648 denial of service in RHEL-7.5
CVE-2019-10171 389-ds-base: Insufficient fix for CVE-2018-14648 denial of service in RHEL-7.5
I was found that the fix present in RHEL-7.5 RHSA-2018:3507 for flaw CVE-2018-14648 was not sufficient.
Other RHEL versions are not affected.
Discussion:
The CVE was partially fixed, following upstream fix was missing in the original RHEL-7.5 build :
https://pagure.io/389-ds-base/c/722a6f8679
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7.5 Extended Update Support
Via RHSA-2019:1789 https://access.redhat.com/errata/RHSA-2019:1789
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-10171
Bugzilla
CVE-2018-14648 389-ds-base: Mishandled search requests in servers/slapd/search.c:do_search() allows for denial of service [fedora-all]
bugzilla·2018-09-21·CVSS 7.5
CVE-2018-14648 [HIGH] CVE-2018-14648 389-ds-base: Mishandled search requests in servers/slapd/search.c:do_search() allows for denial of service [fedora-all]
CVE-2018-14648 389-ds-base: Mishandled search requests in servers/slapd/search.c:do_search() allows for denial of service [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit messa
Bugzilla
CVE-2018-14648 389-ds-base: Mishandled search requests in servers/slapd/search.c:do_search() allows for denial of service
bugzilla·2018-09-19·CVSS 7.5
CVE-2018-14648 [HIGH] CVE-2018-14648 389-ds-base: Mishandled search requests in servers/slapd/search.c:do_search() allows for denial of service
CVE-2018-14648 389-ds-base: Mishandled search requests in servers/slapd/search.c:do_search() allows for denial of service
389 Directory Server is vulnerable to search queries with malformed values in the servers/slapd/search.c:do_search() function. A malicious client could exploit this by sending crafted queries in a loop to cause a denial of service.
Discussion:
Created 389-ds-base tracking bugs for this issue:
Affects: fedora-all [bug 1631695]
---
Sam, is there a upstream issue reference for this issue (and a commit reference)?
---
Hi,
Correcting the needinfo. The assigned engineer is on leave and you should get an update early next week.
Regards
YOG.
---
Created attachment 1491956
fix for v1.3.8.4 (1/2)
---
Created attachment 1491958
additional regression fix for v1.3.8.4
2019-08-02
Published