CVE-2024-1062
published 2024-02-12CVE-2024-1062: A heap overflow flaw was found in 389-ds-base. This issue leads to a denial of service when writing a value larger than 256 chars in log_entry_attr.
PriorityP422medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.30%
22.5th percentile
A heap overflow flaw was found in 389-ds-base. This issue leads to a denial of service when writing a value larger than 256 chars in log_entry_attr.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | 389-ds-base | < 389-ds-base 2.3.4+dfsg1-1 (sid) | 389-ds-base 2.3.4+dfsg1-1 (sid) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| port389 | 389-ds-base | >= 0 < 2.3.4+dfsg1-1 | 2.3.4+dfsg1-1 |
| redhat | 389_directory_server | < 2.2.0 | 2.2.0 |
| redhat | directory_server | — | — |
| redhat | directory_server | — | — |
| redhat | directory_server | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_for_arm_64_eus | — | — |
| redhat | enterprise_linux_for_arm_64_eus | — | — |
| redhat | enterprise_linux_for_arm_64_eus | — | — |
| redhat | enterprise_linux_for_ibm_z_systems | — | — |
| redhat | enterprise_linux_for_ibm_z_systems_eus | — | — |
| redhat | enterprise_linux_for_power_little_endian_eus | — | — |
| redhat | enterprise_linux_for_power_little_endian_eus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_for_power_little_endian_update_services_for_sap_solution | — | — |
| redhat | enterprise_linux_server_for_power_little_endian_update_services_for_sap_solution | — | — |
| redhat | enterprise_linux_server_for_power_little_endian_update_services_for_sap_solution | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6v6c-gc45-x65c: A heap overflow flaw was found in 389-ds-base
ghsa_unreviewed·2024-02-12
CVE-2024-1062 [MEDIUM] CWE-122 GHSA-6v6c-gc45-x65c: A heap overflow flaw was found in 389-ds-base
A heap overflow flaw was found in 389-ds-base. This issue leads to a denial of service when writing a value larger than 256 chars in log_entry_attr.
OSV
CVE-2024-1062: A heap overflow flaw was found in 389-ds-base
osv·2024-02-12·CVSS 5.5
CVE-2024-1062 [MEDIUM] CVE-2024-1062: A heap overflow flaw was found in 389-ds-base
A heap overflow flaw was found in 389-ds-base. This issue leads to a denial of service when writing a value larger than 256 chars in log_entry_attr.
Red Hat
389-ds-base: a heap overflow leading to denail-of-servce while writing a value larger than 256 chars (in log_entry_attr)
vendor_redhat·2024-01-30·CVSS 5.5
CVE-2024-1062 [MEDIUM] CWE-122 389-ds-base: a heap overflow leading to denail-of-servce while writing a value larger than 256 chars (in log_entry_attr)
389-ds-base: a heap overflow leading to denail-of-servce while writing a value larger than 256 chars (in log_entry_attr)
A heap overflow flaw was found in 389-ds-base. This issue leads to a denial of service when writing a value larger than 256 chars in log_entry_attr.
A heap overflow flaw was found in 389-ds-base. This issue leads to a denial of service when writing a value larger than 256 chars in log_entry_attr.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Package: redhat-ds:12/389-ds-base (Red Hat Directory Server 12) - Affected
Package: 389-ds-base (Red Hat Enterprise Linux 6) - Out
Debian
CVE-2024-1062: 389-ds-base - A heap overflow flaw was found in 389-ds-base. This issue leads to a denial of s...
vendor_debian·2024·CVSS 5.5
CVE-2024-1062 [MEDIUM] CVE-2024-1062: 389-ds-base - A heap overflow flaw was found in 389-ds-base. This issue leads to a denial of s...
A heap overflow flaw was found in 389-ds-base. This issue leads to a denial of service when writing a value larger than 256 chars in log_entry_attr.
Scope: local
bookworm: open
bullseye: open
sid: resolved (fixed in 2.3.4+dfsg1-1)
trixie: resolved (fixed in 2.3.4+dfsg1-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/errata/RHSA-2024:1074https://access.redhat.com/errata/RHSA-2024:1372https://access.redhat.com/errata/RHSA-2024:3047https://access.redhat.com/errata/RHSA-2024:4209https://access.redhat.com/errata/RHSA-2024:4633https://access.redhat.com/errata/RHSA-2024:5690https://access.redhat.com/errata/RHSA-2024:7458https://access.redhat.com/errata/RHSA-2025:1632https://access.redhat.com/security/cve/CVE-2024-1062https://bugzilla.redhat.com/show_bug.cgi?id=2256711https://bugzilla.redhat.com/show_bug.cgi?id=2261879https://access.redhat.com/errata/RHSA-2024:1074https://access.redhat.com/errata/RHSA-2024:1372https://access.redhat.com/errata/RHSA-2024:3047https://access.redhat.com/errata/RHSA-2024:4209https://access.redhat.com/errata/RHSA-2024:4633https://access.redhat.com/security/cve/CVE-2024-1062https://bugzilla.redhat.com/show_bug.cgi?id=2256711https://bugzilla.redhat.com/show_bug.cgi?id=2261879
2024-02-12
Published