CVE-2021-3514
published 2021-05-28CVE-2021-3514: When using a sync_repl client in 389-ds-base, an authenticated attacker can cause a NULL pointer dereference using a specially crafted query, causing a crash.
PriorityP433medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
1.18%
64.2th percentile
When using a sync_repl client in 389-ds-base, an authenticated attacker can cause a NULL pointer dereference using a specially crafted query, causing a crash.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | 389-ds-base | < 389-ds-base 1.4.4.11-2 (bookworm) | 389-ds-base 1.4.4.11-2 (bookworm) |
| debian | 389-ds-base | < 389-ds-base 2.3.1-1 (bookworm) | 389-ds-base 2.3.1-1 (bookworm) |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| port389 | 389-ds-base | >= 0 < 1.4.4.11-2 | 1.4.4.11-2 |
| port389 | 389-ds-base | >= 0 < 1.4.4.11-2+deb11u1 | 1.4.4.11-2+deb11u1 |
| port389 | 389-ds-base | >= 0 < 1.4.4.11-2 | 1.4.4.11-2 |
| port389 | 389-ds-base | >= 0 < 2.3.1-1 | 2.3.1-1 |
| port389 | 389-ds-base | >= 0 < 1.4.4.11-2 | 1.4.4.11-2 |
| port389 | 389-ds-base | >= 0 < 2.3.1-1 | 2.3.1-1 |
| port389 | 389-ds-base | >= 0 < 1.3.4.9-1ubuntu0.1~esm1 | 1.3.4.9-1ubuntu0.1~esm1 |
| port389 | 389-ds-base | >= 0 < 1.3.7.10-1ubuntu1+esm1 | 1.3.7.10-1ubuntu1+esm1 |
| port389 | 389-ds-base | >= 0 < 1.4.3.6-2ubuntu0.1~esm1 | 1.4.3.6-2ubuntu0.1~esm1 |
| port389 | 389-ds-base | 2.0.0 – 2.4.1 | — |
| redhat | directory_server | — | — |
| redhat | directory_server | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
389-ds-base: SIGSEGV in sync_repl
vendor_redhat·2022-08-04·CVSS 6.5
CVE-2022-2850 [MEDIUM] CWE-476 389-ds-base: SIGSEGV in sync_repl
389-ds-base: SIGSEGV in sync_repl
A flaw was found In 389-ds-base. When the Content Synchronization plugin is enabled, an authenticated user can reach a NULL pointer dereference using a specially crafted query. This flaw allows an authenticated attacker to cause a denial of service. This CVE is assigned against an incomplete fix of CVE-2021-3514.
A flaw was found In 389-ds-base. When the Content Synchronization plugin is enabled, an authenticated user can reach a NULL pointer dereference using a specially crafted query. This flaw allows an authenticated attacker to cause a denial of service.
Statement: This CVE is assigned against an incomplete fix of CVE-2021-3514.
Package: 389-ds-base (Red Hat Enterprise Linux 6) - Out of support scope
Ubuntu
389 Directory Server vulnerabilities
vendor_ubuntu·2022-07-18·CVSS 5.3
CVE-2020-35518 [MEDIUM] 389 Directory Server vulnerabilities
Title: 389 Directory Server vulnerabilities
Summary: Several security issues were fixed in 389 Directory Server.
It was discovered that 389 Directory Server presented to users, during
authentication, an error message which could be used to discover if a
certain LDAP DN existed or not. A remote unauthenticated attacker could
possibly use this to check the existence of an entry in a LDAP database
and expose sensitive information. This issue affected only Ubuntu 20.04
ESM. (CVE-2020-35518)
It was discovered that 389 Directory Server was incorrectly validating
data used to access memory addresses. An authenticated attacker using a
Syncrepl client could use this issue with a specially crafted query to
cause 389 Directory Server to crash, resulting in a denial of service.
(CVE-2021-3514)
Ins
Debian
CVE-2022-2850: 389-ds-base - A flaw was found In 389-ds-base. When the Content Synchronization plugin is enab...
vendor_debian·2022·CVSS 6.5
CVE-2022-2850 [MEDIUM] CVE-2022-2850: 389-ds-base - A flaw was found In 389-ds-base. When the Content Synchronization plugin is enab...
A flaw was found In 389-ds-base. When the Content Synchronization plugin is enabled, an authenticated user can reach a NULL pointer dereference using a specially crafted query. This flaw allows an authenticated attacker to cause a denial of service. This CVE is assigned against an incomplete fix of CVE-2021-3514.
Scope: local
bookworm: resolved (fixed in 2.3.1-1)
bullseye: resolved (fixed in 1.4.4.11-2+deb11u1)
sid: resolved (fixed in 2.3.1-1)
trixie: resolved (fixed in 2.3.1-1)
Red Hat
389-ds-base: sync_repl NULL pointer dereference in sync_create_state_control()
vendor_redhat·2021-04-01·CVSS 6.5
CVE-2021-3514 [MEDIUM] CWE-476 389-ds-base: sync_repl NULL pointer dereference in sync_create_state_control()
389-ds-base: sync_repl NULL pointer dereference in sync_create_state_control()
When using a sync_repl client in 389-ds-base, an authenticated attacker can cause a NULL pointer dereference using a specially crafted query, causing a crash.
A flaw was found In 389-ds-base. When the Content Synchronization plugin is enabled, an authenticated user can reach a NULL pointer dereference using a specially crafted query. This flaw allows an authenticated attacker to cause a denial of service. The highest threat from this vulnerability is to system availability.
Statement: Red Hat Identity Management is affected by this flaw, as Content Synchronization is enabled by default.
Package: 389-ds-base (Red Hat Enterprise Linux 6) - Out of support scope
Package: 389-ds-base (Red Hat Enterprise Linux 7)
Debian
CVE-2021-3514: 389-ds-base - When using a sync_repl client in 389-ds-base, an authenticated attacker can caus...
vendor_debian·2021·CVSS 6.5
CVE-2021-3514 [MEDIUM] CVE-2021-3514: 389-ds-base - When using a sync_repl client in 389-ds-base, an authenticated attacker can caus...
When using a sync_repl client in 389-ds-base, an authenticated attacker can cause a NULL pointer dereference using a specially crafted query, causing a crash.
Scope: local
bookworm: resolved (fixed in 1.4.4.11-2)
bullseye: resolved (fixed in 1.4.4.11-2)
sid: resolved (fixed in 1.4.4.11-2)
trixie: resolved (fixed in 1.4.4.11-2)
OSV
CVE-2022-2850: A flaw was found In 389-ds-base
osv·2022-10-14·CVSS 6.5
CVE-2022-2850 [MEDIUM] CVE-2022-2850: A flaw was found In 389-ds-base
A flaw was found In 389-ds-base. When the Content Synchronization plugin is enabled, an authenticated user can reach a NULL pointer dereference using a specially crafted query. This flaw allows an authenticated attacker to cause a denial of service. This CVE is assigned against an incomplete fix of CVE-2021-3514.
GHSA
GHSA-6c63-4574-7p9f: A flaw was found In 389-ds-base
ghsa_unreviewed·2022-10-14·CVSS 6.5
CVE-2022-2850 [MEDIUM] CWE-476 GHSA-6c63-4574-7p9f: A flaw was found In 389-ds-base
A flaw was found In 389-ds-base. When the Content Synchronization plugin is enabled, an authenticated user can reach a NULL pointer dereference using a specially crafted query. This flaw allows an authenticated attacker to cause a denial of service. This CVE is assigned against an incomplete fix of CVE-2021-3514.
OSV
389-ds-base vulnerabilities
osv·2022-07-18·CVSS 5.3
CVE-2020-35518 [MEDIUM] 389-ds-base vulnerabilities
389-ds-base vulnerabilities
It was discovered that 389 Directory Server presented to users, during
authentication, an error message which could be used to discover if a
certain LDAP DN existed or not. A remote unauthenticated attacker could
possibly use this to check the existence of an entry in a LDAP database
and expose sensitive information. This issue affected only Ubuntu 20.04
ESM. (CVE-2020-35518)
It was discovered that 389 Directory Server was incorrectly validating
data used to access memory addresses. An authenticated attacker using a
Syncrepl client could use this issue with a specially crafted query to
cause 389 Directory Server to crash, resulting in a denial of service.
(CVE-2021-3514)
GHSA
GHSA-4mjm-c95j-8748: When using a sync_repl client in 389-ds-base, an authenticated attacker can cause a NULL pointer dereference using a specially crafted query, causing
ghsa_unreviewed·2022-05-24
CVE-2021-3514 [MEDIUM] CWE-476 GHSA-4mjm-c95j-8748: When using a sync_repl client in 389-ds-base, an authenticated attacker can cause a NULL pointer dereference using a specially crafted query, causing
When using a sync_repl client in 389-ds-base, an authenticated attacker can cause a NULL pointer dereference using a specially crafted query, causing a crash.
OSV
CVE-2021-3514: When using a sync_repl client in 389-ds-base, an authenticated attacker can cause a NULL pointer dereference using a specially crafted query, causing
osv·2021-05-28·CVSS 6.5
CVE-2021-3514 [MEDIUM] CVE-2021-3514: When using a sync_repl client in 389-ds-base, an authenticated attacker can cause a NULL pointer dereference using a specially crafted query, causing
When using a sync_repl client in 389-ds-base, an authenticated attacker can cause a NULL pointer dereference using a specially crafted query, causing a crash.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-05-28
Published