CVE-2019-10171
published 2019-08-02CVE-2019-10171: It was found that the fix for CVE-2018-14648 in 389-ds-base, versions 1.4.0.x before 1.4.0.17, was incorrectly applied in RHEL 7.5. An attacker would still be…
PriorityP336high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.37%
68.8th percentile
It was found that the fix for CVE-2018-14648 in 389-ds-base, versions 1.4.0.x before 1.4.0.17, was incorrectly applied in RHEL 7.5. An attacker would still be able to provoke excessive CPU consumption leading to a denial of service.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | 389-ds-base | — | — |
| fedoraproject | 389_directory_server | >= 1.4.0.0 < 1.4.0.17 | 1.4.0.17 |
| redhat | enterprise_linux_server_eus | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
389-ds-base: Insufficient fix for CVE-2018-14648 denial of service in RHEL-7.5
vendor_redhat·2019-06-19·CVSS 7.5
CVE-2019-10171 [HIGH] CWE-770 389-ds-base: Insufficient fix for CVE-2018-14648 denial of service in RHEL-7.5
389-ds-base: Insufficient fix for CVE-2018-14648 denial of service in RHEL-7.5
It was found that the fix for CVE-2018-14648 in 389-ds-base, versions 1.4.0.x before 1.4.0.17, was incorrectly applied in RHEL 7.5. An attacker would still be able to provoke excessive CPU consumption leading to a denial of service.
It was found that the fix for CVE-2018-14648 was incorrectly applied in RHEL 7.5. An attacker would still be able to provoke excessive CPU consumption leading to a denial of service.
Package: 389-ds-base (Red Hat Enterprise Linux 7) - Affected
Debian
CVE-2019-10171: 389-ds-base - It was found that the fix for CVE-2018-14648 in 389-ds-base, versions 1.4.0.x be...
vendor_debian·2019·CVSS 7.5
CVE-2019-10171 [HIGH] CVE-2019-10171: 389-ds-base - It was found that the fix for CVE-2018-14648 in 389-ds-base, versions 1.4.0.x be...
It was found that the fix for CVE-2018-14648 in 389-ds-base, versions 1.4.0.x before 1.4.0.17, was incorrectly applied in RHEL 7.5. An attacker would still be able to provoke excessive CPU consumption leading to a denial of service.
Scope: local
bookworm: resolved
bullseye: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-9cc6-43cm-mf7x: It was found that the fix for CVE-2018-14648 in 389-ds-base, versions 1
ghsa_unreviewed·2022-05-24·CVSS 7.5
CVE-2019-10171 [HIGH] CWE-770 GHSA-9cc6-43cm-mf7x: It was found that the fix for CVE-2018-14648 in 389-ds-base, versions 1
It was found that the fix for CVE-2018-14648 in 389-ds-base, versions 1.4.0.x before 1.4.0.17, was incorrectly applied in RHEL 7.5. An attacker would still be able to provoke excessive CPU consumption leading to a denial of service.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-9064 389-ds-base: 389-ds-base: unbounded LDAP controls count in get_ldapmessage_controls_ext() causes CPU and heap amplification (remote DoS)
bugzilla·2026-05-20·CVSS 7.5
CVE-2026-9064 [HIGH] CVE-2026-9064 389-ds-base: 389-ds-base: unbounded LDAP controls count in get_ldapmessage_controls_ext() causes CPU and heap amplification (remote DoS)
CVE-2026-9064 389-ds-base: 389-ds-base: unbounded LDAP controls count in get_ldapmessage_controls_ext() causes CPU and heap amplification (remote DoS)
A vulnerability was found in 389-ds-base (389 Directory Server). The function get_ldapmessage_controls_ext() in ldap/servers/slapd/control.c parses the optional LDAP v3 Controls field via a decode loop that allocates one LDAPControl struct per control element and grows the pointer list with repeated reallocations, but does not enforce a hard upper bound on the number of controls per message.
Under the default nsslapd-maxbersize of 2097152 (2 MB), a remote unauthenticated client can encode hundreds of thousands of minimal non-critical controls in a single LDAP request, forcing attacker-amplified CPU time and heap allocation. The control par
Bugzilla
CVE-2019-10171 389-ds-base: Insufficient fix for CVE-2018-14648 denial of service in RHEL-7.5
bugzilla·2019-06-19·CVSS 7.5
CVE-2019-10171 [HIGH] CVE-2019-10171 389-ds-base: Insufficient fix for CVE-2018-14648 denial of service in RHEL-7.5
CVE-2019-10171 389-ds-base: Insufficient fix for CVE-2018-14648 denial of service in RHEL-7.5
I was found that the fix present in RHEL-7.5 RHSA-2018:3507 for flaw CVE-2018-14648 was not sufficient.
Other RHEL versions are not affected.
Discussion:
The CVE was partially fixed, following upstream fix was missing in the original RHEL-7.5 build :
https://pagure.io/389-ds-base/c/722a6f8679
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7.5 Extended Update Support
Via RHSA-2019:1789 https://access.redhat.com/errata/RHSA-2019:1789
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-10171
2019-08-02
Published