CVE-2024-2199
published 2024-09-05CVE-2024-2199: The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios. In certain product versions, an authenticated user may cause a server crash…
PriorityP421medium5.7CVSS 3.1
AVAACLPRLUINSUCNINAH
EPSS
0.56%
43.3th percentile
The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios. In certain product versions, an authenticated user may cause a server crash while modifying `userPassword` using malformed input.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | 389-ds-base | < 389-ds-base 2.0.11-1 (bookworm) | 389-ds-base 2.0.11-1 (bookworm) |
| debian | 389-ds-base | < 389-ds-base 2.3.1+dfsg1-1+deb12u1 (bookworm) | 389-ds-base 2.3.1+dfsg1-1+deb12u1 (bookworm) |
| port389 | 389-ds-base | >= 0 < 1.4.4.11-2+deb11u1 | 1.4.4.11-2+deb11u1 |
| port389 | 389-ds-base | >= 0 < 2.0.11-1 | 2.0.11-1 |
| port389 | 389-ds-base | >= 0 < 2.3.1+dfsg1-1+deb12u1 | 2.3.1+dfsg1-1+deb12u1 |
| port389 | 389-ds-base | >= 0 < 2.0.11-1 | 2.0.11-1 |
| port389 | 389-ds-base | >= 0 < 3.1.1+dfsg1-1 | 3.1.1+dfsg1-1 |
CVSS provenance
nvdv3.15.7MEDIUMCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.7MEDIUM
vendor_debian5.7MEDIUM
vendor_redhat5.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: f2fs: fix to avoid potential deadlock in f2fs_record_stop_reason()
vendor_redhat·2024-12-29·CVSS 5.5
CVE-2024-56744 [MEDIUM] CWE-667 kernel: f2fs: fix to avoid potential deadlock in f2fs_record_stop_reason()
kernel: f2fs: fix to avoid potential deadlock in f2fs_record_stop_reason()
In the Linux kernel, the following vulnerability has been resolved:
f2fs: fix to avoid potential deadlock in f2fs_record_stop_reason()
syzbot reports deadlock issue of f2fs as below:
WARNING: possible circular locking dependency detected
6.12.0-rc3-syzkaller-00087-gc964ced77262 #0 Not tainted
kswapd0/79 is trying to acquire lock:
ffff888011824088 (&sbi->sb_lock){++++}-{3:3}, at: f2fs_down_write fs/f2fs/f2fs.h:2199 [inline]
ffff888011824088 (&sbi->sb_lock){++++}-{3:3}, at: f2fs_record_stop_reason+0x52/0x1d0 fs/f2fs/super.c:4068
but task is already holding lock:
ffff88804bd92610 (sb_internal#2){.+.+}-{0:0}, at: f2fs_evict_inode+0x662/0x15c0 fs/f2fs/inode.c:842
which lock already depends on the new lock.
the existing
Red Hat
389-ds-base: server crash while modifying `userPassword` using malformed input (Incomplete fix for CVE-2024-2199)
vendor_redhat·2024-09-05·CVSS 5.7
CVE-2024-8445 [MEDIUM] CWE-20 389-ds-base: server crash while modifying `userPassword` using malformed input (Incomplete fix for CVE-2024-2199)
389-ds-base: server crash while modifying `userPassword` using malformed input (Incomplete fix for CVE-2024-2199)
The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios. In certain product versions, an authenticated user may cause a server crash while modifying `userPassword` using malformed input.
The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios. In certain product versions, an authenticated user may cause a server crash while modifying `userPassword` using malformed input.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Package: red
Red Hat
389-ds-base: Malformed userPassword may cause crash at do_modify in slapd/modify.c
vendor_redhat·2024-05-28·CVSS 5.7
CVE-2024-2199 [MEDIUM] CWE-20 389-ds-base: Malformed userPassword may cause crash at do_modify in slapd/modify.c
389-ds-base: Malformed userPassword may cause crash at do_modify in slapd/modify.c
A denial of service vulnerability was found in 389-ds-base ldap server. This issue may allow an authenticated user to cause a server crash while modifying `userPassword` using malformed input.
A denial of service vulnerability was found in 389-ds-base ldap server. This issue may allow an authenticated user to cause a server crash while modifying `userPassword` using malformed input.
Statement: LDAP servers are not usually exposed to the open internet, requiring adjacent connectivity for a successful attack. This issue also requires a compromised user account to perform the attack. Therefore, this flaw is rated as a Moderate severity.
Mitigation: Mitigation for this issue is either not available or the cu
Debian
CVE-2024-8445: 389-ds-base - The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios...
vendor_debian·2024·CVSS 5.7
CVE-2024-8445 [MEDIUM] CVE-2024-8445: 389-ds-base - The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios...
The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios. In certain product versions, an authenticated user may cause a server crash while modifying `userPassword` using malformed input.
Scope: local
bookworm: resolved (fixed in 2.0.11-1)
bullseye: resolved (fixed in 1.4.4.11-2+deb11u1)
sid: resolved (fixed in 2.0.11-1)
trixie: resolved (fixed in 2.0.11-1)
Debian
CVE-2024-2199: 389-ds-base - A denial of service vulnerability was found in 389-ds-base ldap server. This iss...
vendor_debian·2024·CVSS 5.7
CVE-2024-2199 [MEDIUM] CVE-2024-2199: 389-ds-base - A denial of service vulnerability was found in 389-ds-base ldap server. This iss...
A denial of service vulnerability was found in 389-ds-base ldap server. This issue may allow an authenticated user to cause a server crash while modifying `userPassword` using malformed input.
Scope: local
bookworm: resolved (fixed in 2.3.1+dfsg1-1+deb12u1)
bullseye: resolved (fixed in 1.4.4.11-2+deb11u1)
sid: resolved (fixed in 3.1.1+dfsg1-1)
trixie: resolved (fixed in 3.1.1+dfsg1-1)
GHSA
GHSA-9q6m-vr5h-rqq5: The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios
ghsa_unreviewed·2024-09-05·CVSS 5.7
CVE-2024-8445 [MEDIUM] CWE-20 GHSA-9q6m-vr5h-rqq5: The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios
The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios. In certain product versions, an authenticated user may cause a server crash while modifying `userPassword` using malformed input.
OSV
CVE-2024-8445: The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios
osv·2024-09-05·CVSS 5.7
CVE-2024-8445 [MEDIUM] CVE-2024-8445: The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios
The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios. In certain product versions, an authenticated user may cause a server crash while modifying `userPassword` using malformed input.
OSV
CVE-2024-2199: A denial of service vulnerability was found in 389-ds-base ldap server
osv·2024-05-28·CVSS 5.7
CVE-2024-2199 [MEDIUM] CVE-2024-2199: A denial of service vulnerability was found in 389-ds-base ldap server
A denial of service vulnerability was found in 389-ds-base ldap server. This issue may allow an authenticated user to cause a server crash while modifying `userPassword` using malformed input.
No detection rules found.
No public exploits indexed.
2024-09-05
Published